Skip to content
AwareSprint

Security

Security training from people who take security seriously

AwareSprint is built by Cyberneticsplus, a firm that spends its days breaking into systems with permission. We hold ourselves to the standard we test other companies against, and this page says exactly what that means in practice.

Controls in place on this site today

Not aspirations. These are live on the page you are reading, and you can verify every one of them from your browser.

Encrypted everywhere

All traffic runs over TLS, with strict transport security enforced so browsers refuse to connect insecurely.

Strict content security policy

Browsers are told to load nothing from third parties except our analytics tag. No CDNs, no ad networks, no embedded widgets. Fonts and icons are served from our own domain.

Analytics only, and only if you agree

One analytics cookie, and only after you accept it. Consent starts denied, advertising signals are switched off permanently, and we run no advertising anywhere.

Minimal data by design

Registration takes a work email address and nothing else. The challenge itself adds a display name and progress. No passwords are ever stored, for anyone.

Small attack surface

The site is statically generated and served from edge infrastructure. There is no application server, no database of accounts and no admin panel to break into.

Abuse resistance built in

Forms carry invisible traps that catch automated submissions, and every entry is validated at the edge before anything is stored.

Found a vulnerability?

We want to hear about it, directly and first. Write to security@awaresprint.com with enough detail to reproduce the issue. A machine readable disclosure file is published at the standard location on this domain.

We respond to good faith reports, we do not play games with researchers, and we credit people who help us unless they prefer otherwise. Please avoid accessing data that is not yours and give us reasonable time to fix what you find before talking about it publicly.

What a useful report includes

  • The URL or endpoint affected
  • Steps to reproduce, as specifically as you can
  • What you expected and what actually happened
  • Impact as you understand it
  • How you would like to be credited