Security & Responsible Disclosure
We take the security of ScanRub seriously and welcome reports from the security community. This page is our public security policy and responsible-disclosure program.
Reporting a vulnerability
Email security@scanrub.com with:
- A clear description and impact assessment.
- Reproduction steps or a proof of concept.
- The affected URL, parameter, or component.
Our machine-readable policy lives at /.well-known/security.txt.
Our commitment
- We will acknowledge your report within 2 business days.
- We will provide a triage decision and severity within 5 business days.
- We will keep you updated through remediation and credit you (with your consent).
Safe harbor
We will not pursue or support legal action against researchers who:
- Act in good faith and avoid privacy violations, data destruction, or service degradation.
- Only interact with accounts they own or have explicit permission to access.
- Give us reasonable time to remediate before public disclosure.
Scope
In scope: scanrub.com, app.scanrub.com, api.scanrub.com. Out of scope: volumetric DoS, social engineering, and findings requiring physical access.
A note on our own product
ScanRub is a scanning platform. Using it against systems you are not authorized to test is prohibited by our Terms. Our research content is published for defensive and educational use.