scanrub
Trust & Security

Security & Responsible Disclosure

We take the security of ScanRub seriously and welcome reports from the security community. This page is our public security policy and responsible-disclosure program.

Reporting a vulnerability

Email security@scanrub.com with:

  • A clear description and impact assessment.
  • Reproduction steps or a proof of concept.
  • The affected URL, parameter, or component.

Our machine-readable policy lives at /.well-known/security.txt.

Our commitment

  • We will acknowledge your report within 2 business days.
  • We will provide a triage decision and severity within 5 business days.
  • We will keep you updated through remediation and credit you (with your consent).

Safe harbor

We will not pursue or support legal action against researchers who:

  • Act in good faith and avoid privacy violations, data destruction, or service degradation.
  • Only interact with accounts they own or have explicit permission to access.
  • Give us reasonable time to remediate before public disclosure.

Scope

In scope: scanrub.com, app.scanrub.com, api.scanrub.com. Out of scope: volumetric DoS, social engineering, and findings requiring physical access.

A note on our own product

ScanRub is a scanning platform. Using it against systems you are not authorized to test is prohibited by our Terms. Our research content is published for defensive and educational use.

Weekly security research

New vulnerability playbooks, tool updates, and bug bounty insights - delivered to your inbox. No spam.

Unsubscribe anytime. We respect your inbox.
Press ⌘K to search×