Report a vulnerability

We build security products, so we treat reports about our own software as first-class work. This page tells you where to send a finding, what happens next, and what we promise in return — and, at the end, where to report someone aiming SelfSec at systems they had no business touching.

How to report

Email [email protected] with SECURITY in the subject line. A machine-readable pointer to this policy is published at /.well-known/security.txt.

A report we can act on quickly includes the affected product and version or URL, the steps to reproduce, the request and response that demonstrate the issue, and what an attacker gains. If you have a proof of concept, keep it minimal — enough to prove impact, no more.

Reporting something different? If someone aimed SelfSec at systems you are responsible for, go straight to reporting abuse of SelfSec tools.

What we will not ask you to do

You do not need to attack our production edge to file a report. selfsec.io runs behind SelfSec WAF with rate limiting and automatic banning, so sustained probing will simply block your address without teaching either of us anything. If a finding requires live testing to demonstrate, tell us and we will agree on a window and a target with you first.

In scope

  • selfsec.io and the account platform behind it
  • SelfSec DAST — the local scanner and its account activation flow
  • SelfSec WAF — the reverse proxy, its rule handling and its telemetry flow
  • The account session, entitlement and subscription APIs

Out of scope

  • Denial of service, volumetric load testing and resource-exhaustion attempts
  • Social engineering, phishing or physical access against us or our users
  • Findings against third-party services we merely link to
  • Reports with no demonstrated impact — missing headers, version disclosure, self-XSS or automated scanner output pasted without analysis

Safe harbor

If you make a good-faith effort to follow this policy, we will not pursue or support legal action against you for your research, and we will treat your report as authorized testing. Good faith means: you stop at proof of impact, you do not access, modify or exfiltrate data that is not yours, you do not degrade the service for others, and you give us a reasonable chance to fix the issue before you publish.

Coordinated disclosure

We aim to ship a fix within 90 days of triage and are happy to coordinate a joint publication date. If a fix will take longer, we will tell you why rather than let the clock run out silently. We do not currently run a paid bug bounty; with your permission we credit reporters in the release notes for the version that carries the fix.

Reporting abuse of SelfSec tools

Our terms allow scanning only against systems the customer owns or has explicit authorization to test. If you believe someone used SelfSec against systems you are responsible for without that authorization, email [email protected]. This is a different address from the vulnerability contact above, and it is the fastest route to someone who can act.

Include as much of the following as you have:

  • The hostname that was targeted — this is the single most useful detail — and the address the traffic came from
  • The time window, with the time zone — start and end, as precisely as your logs allow
  • A log excerpt showing the requests, including any User-Agent or header that identifies the tool
  • What the traffic did, and whether it caused disruption

We acknowledge abuse reports within 3 working days. Where we can tie the activity to an account, we suspend it while we investigate, and we preserve and disclose account records when a competent authority asks for them lawfully. We will tell you what action we took, though we will not disclose a customer's identity to you directly — that goes to the authorities, not the reporter.

One limit worth knowing up front: the SelfSec scanner is self-hosted software that runs on the customer's own machine, so scan traffic never passes through us and we cannot reconstruct a scan from our side. Your logs are the evidence, which is why the details above matter — the targeted hostname most of all, because that is what we can search our own records for. We hold only a partial, incidental record of what any account scanned, so a match is likely but never guaranteed.

What to expect after you report

Within 3 working days

A human acknowledges your report and tells you who is handling it.

Within 10 working days

A triage result: reproduced or not, severity, and whether it is in scope.

While we fix it

Progress updates at least every 14 days until the issue is resolved or closed with a reason.