Report a vulnerability
We build security products, so we treat reports about our own software as first-class work. This page tells you where to send a finding, what happens next, and what we promise in return — and, at the end, where to report someone aiming SelfSec at systems they had no business touching.
Security contact
[email protected]Put SECURITY in the subject line so the report reaches the right queue.
What to expect after you report
- Within 3 business days
- A human acknowledges your report and tells you who is handling it.
- Within 10 business days
- A triage result: reproduced or not, severity, and whether it is in scope.
- While we fix it
- Progress updates at least every 14 days until the issue is resolved or closed with a reason.
How to report
Email [email protected] with SECURITY in the subject line. A machine-readable pointer to this policy is published at /.well-known/security.txt.
A report we can act on quickly includes the affected product and version or URL, the steps to reproduce, the request and response that demonstrate the issue, and what an attacker gains. If you have a proof of concept, keep it minimal — enough to prove impact, no more.
Reporting something different? If someone aimed SelfSec at systems you are responsible for, go straight to reporting abuse of SelfSec tools.
What we will not ask you to do
You do not need to attack this site to file a report. selfsec.io runs behind a reverse-proxy firewall we operate ourselves, with rate limiting and automatic banning, so sustained probing will simply block your address without teaching either of us anything. If a finding requires live testing to demonstrate, tell us and we will agree on a window and a target with you first.
In scope
- selfsec.io and the account platform behind it
- The SelfSec scanner — the local app and its account activation flow
- The reverse proxy in front of selfsec.io — we wrote and run it, so a bypass or a flaw in it is in scope
- The account session, entitlement and subscription APIs
Out of scope
- Denial of service, volumetric load testing and resource-exhaustion attempts
- Social engineering, phishing or physical access against us or our users
- Findings against third-party services we merely link to
- Reports with no demonstrated impact — missing headers, version disclosure, self-XSS or automated scanner output pasted without analysis
Safe harbor
If you make a good-faith effort to follow this policy, we will not pursue or support legal action against you for your research, and we will treat your report as authorized testing. Good faith means: you stop at proof of impact, you do not access, modify or exfiltrate data that is not yours, you do not degrade the service for others, and you give us a reasonable chance to fix the issue before you publish.
Coordinated disclosure
We aim to ship a fix within 90 days of triage and are happy to coordinate a joint publication date. If a fix will take longer, we will tell you why rather than let the clock run out silently. We do not currently run a paid bug bounty; with your permission we credit reporters in the release notes for the version that carries the fix.
Reporting abuse of SelfSec tools
Our terms allow scanning only against systems the customer owns or has explicit authorization to test. If you believe someone used SelfSec against systems you are responsible for without that authorization, email [email protected]. This is a different address from the vulnerability contact above, and it is the fastest route to someone who can act.
Include as much of the following as you have:
- The hostname that was targeted and the address the traffic came from — for your record and any authority you involve, since we cannot trace either back to an account
- The time window, with the time zone — start and end, as precisely as your logs allow
- A log excerpt showing the requests, including any User-Agent or header that identifies the tool
- What the traffic did, and whether it caused disruption
We acknowledge abuse reports within 3 business days. We preserve and disclose account records when a competent authority asks for them lawfully, and we will tell you what action we took, though we will not disclose a customer's identity to you directly — that goes to the authorities, not the reporter.
One limit worth knowing up front, and it is a hard one: the SelfSec scanner is self-hosted software that runs on the customer's own machine. Scan traffic never passes through us, and we hold no record at all of what any account scanned — not a partial one, not an incidental one. We cannot look a hostname up and find the account behind it. Your logs are the evidence, and the details above matter for your own records and for any authority you involve, not for a lookup on our side. What we can do is act on the account records we do hold, and cooperate with a lawful request about them.