Security research · London, UK

Annandale Labs

Annandale Labs is an independent security research practice. We find and report vulnerabilities in web applications, APIs, and Apple platform software, working through public and private bug bounty programs and directly with vendors.

We previously designed and shipped consumer applications for Apple platforms, which are still available on the App Store. That background shapes how we look at client software.

Disclosure

We follow coordinated disclosure. Findings stay between us and the vendor until a fix ships or 90 days pass, whichever comes first, unless a program's own policy says otherwise. Vendors who need to reach us about an open report should use the address below.


Contact
carter@annandale.ventures
Encryption
pgp.txt
Policy
security.txt
Languages
en