Charter

The Sentinel's Rules

Ten rules the Sentinel works and writes by. They exist so that readers can check the work — and so the Sentinel can be held to them.

  1. Authorized work only

    Every technique shown was used in the Sentinel's own labs, in CTFs, in bug bounties within program rules, or in engagements the Sentinel was paid and permitted to run. Nothing else.

  2. Disclosure comes before publication

    Findings are written up only after they are patched, published by the vendor, or released under a coordinated disclosure process in line with ISO/IEC 29147 and the CERT/CC guide — never before, and never in violation of a program's terms.

  3. Composites are labeled composites

    Real experience is real, but no client, employer, or colleague is ever identifiable. War stories are merged, altered accounts — and every one carries a composite notice.

  4. Sources are attributed

    Quotations are quoted and credited. Facts lean on primary sources: standards bodies, vendor advisories, original research. If the Sentinel can't cite it, the Sentinel says so instead of dressing a hunch as fact.

  5. Labs before claims

    Offensive content is demonstrated in lab recreations, with the environment and limits stated. Screenshots and traces come from the lab, not from anyone's production systems.

  6. No exploit retail

    No working 0-days, no weaponized payloads, no "DM me for the PoC." If a detail would mainly help an attacker and not a defender, it stays out.

  7. Mistakes get corrections

    Errors are corrected in place, marked with an updated date, and never silently rewritten. The archive is a record, not a brochure.

  8. No fear-selling

    No fake urgency, no "you'll be hacked by Friday," no CVSS theater. Risk is described in plain terms with realistic likelihoods, because fear is a tax on readers.

  9. Anonymity is not impunity

    The Sentinel writes anonymously, which lowers the cost of candor — it does not lower the standard. The same laws, ethics, and program rules apply; anonymity only protects a name, never a practice.

  10. Reader autonomy over engagement

    Monetization, when it arrives, will be disclosed on this site's Disclosures page before it appears in the feed. Sponsorship never buys a verdict.

Sources & attributions

  1. ISO/IEC 29147:2018, Information technology — Security techniques — Vulnerability disclosure, iso.org/standard/72311 — the standard this charter's disclosure rule follows.
  2. ISO/IEC 30111:2019, Vulnerability handling and disclosure processes, iso.org/standard/71729.
  3. Householder, Garfinkel et al., Guidelines on Vulnerability Disclosure, CERT/CC CMU/SEI-2017-SR-013 (v1.2, 2024), resources.sei.cmu.edu.
  4. Electronic Frontier Foundation, Defending Privacy at the U.S. Border and anonymity writing generally — eff.org/issues/anonymity — background for Rule 9.