Reporting a vulnerability
Send a concise report to security@scanlyst.dev with the affected URL or component, reproduction steps, impact, and any supporting evidence. Do not include secrets or personal data unless necessary; use encrypted communication when available.
Safe-harbor expectations
- Make a good-faith effort to avoid privacy violations, data destruction, service disruption, and access beyond what is needed to demonstrate the issue.
- Do not use denial-of-service testing, social engineering, physical attacks, automated high-volume scanning, or third-party compromise.
- Give us reasonable time to investigate and remediate before public disclosure.
- Stop testing and notify us if you encounter sensitive data or unexpected access.
Our response
We aim to acknowledge actionable reports, investigate them, and communicate material progress. We do not currently promise monetary rewards. Eligibility for recognition is determined case by case.
Scope
Testing is limited to Scanlyst-controlled systems. Customer websites, third-party services, social engineering, and vendor infrastructure are outside scope unless we explicitly confirm otherwise in writing.