The Ethical Reporting OrganizationOrg.

Found a bug? Exploit Discovered? Have no idea who to tell?

Let us stand on your behalf!

Find Out More

About us


About ERO

Who we are

Our mission is to proactively prevent some kid who just found something cool, not quite knowing that he walks a fine line while nurturing his newly found love of computers, from ending up on the wrong side of the court room.

What we do

We stand to protect the members of the Information Security field who stumble across something in the wild that just didn't seem quite right, knowing what they know, ethically bound, they must tell.

Saw something, want to say something? Get a hold of us and we will do what is within our power to correct the situation.

Contact us


PGP Key

This Key Expires: 7 October 2016


There are 2 rules for contacting us:


  1. 1. You do not have to identify yourself.
  2. 2. DO NOT SEND CLASSIFIED ANYTHING OF ANY SORTS. THERE IS A PROPER WAY TO HANDLE THIS, AND WE ARE MORE THAN HAPPY TO PROVIDE GUIDANCE ON SUCH MATTERS.
    •     Email us, informing us of ONLY the agency involved. We will take it from there and provide a response as soon as possible.