Security & Responsible Disclosure

We investigate cybercrime for a living, so we take reports about our own exposure seriously. If you believe you have found a security vulnerability on countervailintelligence.com, we want to hear about it.

How to report a vulnerability

Email contact@countervailintelligence.com with “Security report” in the subject line. Please include the affected page or URL, what you found, steps to reproduce it, and how we can reach you. We will acknowledge your report and keep you updated as we work on it.

Please don’t

  • Access, change, or delete data that isn’t yours, including any client information
  • Run denial-of-service, spam, or social engineering tests against us, our clients, or our providers
  • Test Stripe, Google, or WordPress.com infrastructure; report issues in those platforms to the provider directly
  • Share details publicly before we have had a reasonable chance to fix the issue

Is it really us?

Criminals impersonate investigators and recovery firms, especially to victims who have already lost money. All payments go to Countervail LLC, either through a secure Stripe checkout link on buy.stripe.com or an invoice on our letterhead. We will never ask for your passwords, recovery codes, or seed phrases, never ask you to install remote-access software, and never ask you to pay in gift cards, cryptocurrency, or by wire to an individual. Our fees are never a percentage of recovered funds, and anyone who guarantees to get your money back is not us.

If a message claiming to be from Countervail feels off, call (509) 393-0896 before you act, or contact us through this website.