Responsible Disclosure

Last updated

This is a single-operator service rather than a large vendor platform, so there is no bug bounty program. What follows is the expectation for reporting a vulnerability in it anyway.

Draft. Written to accurately describe this application's actual behavior, but not reviewed by qualified legal counsel — treat it as technical documentation rather than a finished legal document.
On this page

Scope

Security issues in this codebase — authentication, session handling, access control between accounts, the SSRF guards, the scan input validation, or the audit chain — are in scope. So are issues in a specific deployment's configuration, reported to whoever runs that deployment.

Findings that this application reports about your own scanned targets are not disclosures against this project; those are simply scan results.

How to report

  • Report it to whoever operates the specific deployment you found it in, privately, before any public disclosure.
  • Do not access, modify, or exfiltrate data belonging to a deployment you don't operate or have explicit written authorization to test.
  • Give the operator reasonable time to remediate before disclosing publicly.
  • Include enough detail to reproduce: the affected route or component, the account role you were using, and what you expected to happen instead.

Already-known issues

Before reporting, check the Security Policy. Its known-limitations section documents the gaps that are already understood and deliberately disclosed — no encryption at rest, in-memory rate limiting, the residual DNS-rebinding window on webhook delivery, and the audit chain living in the database it protects, among others. A report that restates one of those is still welcome, but it will not be news.

If you operate a deployment

If you are standing this application up for a team or organization, replace this page with your actual security contact — an email address or a security.txt reference — before anyone relies on it. A disclosure policy with no reachable contact is worse than none, because it implies one exists.

Contact

Talk to us.

Questions about what the engine checks, whether it fits your estate, or what it deliberately refuses to do. A person reads every message.

  1. 01You writePlain form, no qualifying call, no obligation. The marketing checkbox is optional and unticked.
  2. 02A person reads itMessages land with the team, not a queue-bot. Nothing is auto-replied.
  3. 03You get an answerTo the address you gave — including “this product is not the right fit”, when that is the honest answer.
Prefer email?
Use the form — no address is published on this deployment.
Reporting a vulnerability?
Read the disclosure policy first — it tells you what is in scope and what to expect.
New messagereplies go to your email

Personal addresses (gmail, outlook, and similar) are not accepted.

+91

0 / 4000