Security Hall of Fame

Effective 4 September 2026 Version 1.0 Reports made under the Responsible Disclosure Policy

The researchers who have reported a valid vulnerability in ShellOrbit and chosen to be named. This is the whole reward we can offer, so we take it seriously.

We do not pay for vulnerability reports. Credit here is what we offer instead, so it is not handed out loosely and it is not taken down later.

Every researcher listed below reported a real, previously unreported vulnerability in ShellOrbit under our Responsible Disclosure Policy, and asked to be named.

The list

No entries yet.

ShellOrbit is new, and nobody has reported a confirmed vulnerability to us so far. This page exists because the offer is real and we would rather publish it empty than write it after the fact. The first name here is available.

How a name gets here

  • You report something to security@shellorbit.com under the disclosure policy.
  • We confirm it is real, previously unreported, and in scope.
  • We fix it.
  • We add you, using the name or handle you asked for, with a short description of the class of issue and the month it was reported.

We list the class of issue, never a reproduction. A fixed bug in one system is often an unfixed bug in another, and a hall of fame should not double as a lookup table for attacking somebody else.

You can ask to stay anonymous, and plenty of people do. A report is no less welcome for it, and it does not change how we handle the issue. You can also ask us to remove your entry later, and we will.

What we will not do

We will not add a name for a report that turned out to be a duplicate, out of scope, or not a vulnerability. That is not a judgment on the effort involved, and we will always explain the reasoning. It is only that a credit which is given to everybody means nothing to anybody.

We do not accept submissions asking for credit in exchange for a scanner report with no demonstrated impact, and we do not issue letters, certificates, or bounty-platform points.