Report a vulnerability in Helix Counter.
If you have found a flaw in this platform, this is the door. The program below is published by the running deployment, not written on this page — what you read here is what the software will actually hold itself to.
The disclosure program
Published by the deployment · GET /v1/trust/vdp
Reading the published program…
Send a report
Anonymous by design — no account, no API key. POST /v1/trust/report
How we think about this
Published documents · no account, no form
The trust & assurance brief (4 pp) is the review team's document: how the platform is built, tested and operated, what you can verify without taking our word, and what is still outstanding. Three of the Notes on Active Defense bear on this page directly — the vendor is part of your attack surface, what we do not detect, and compiling what you learn.
Published advisories
Every advisory this deployment has published · GET /v1/trust/advisories
Reading published advisories…
Machine-readable
RFC 9116
Automated tooling should read /.well-known/security.txt, which is generated from the live program on every request — so its Expires is always current and it can never advertise contacts the program has stopped honouring. It returns 404 for the same reason this page shows no form when nothing is declared.