Skip to main content

Report a security issue to us privately

If you have found something that should not be public, we want to hear about it before anybody else does. This page says where to send it and what happens after you do.

Where to send it

contact@scalaralabs.com

We acknowledge a report within five working days and keep you updated until it is closed.

The same address is published in our security.txt file. If the two ever disagree, the file is the one to trust and we would like to know.

Scope, and what we ask of you

We do not run a paid bug bounty. We do read every report, we reply to every report, and we credit anybody who wants credit once an issue is closed.

What is in scope

  • This website and the addresses it serves.
  • The lead endpoint the demo and contact forms post to.
  • The content admin and the preview route that sits behind it.
  • Our published DNS, mail and transport security configuration.

What is out of scope

  • Anything hosted by a partner rather than by us. Tell us anyway and we will pass it on with your permission rather than leaving you to find the right address.
  • Reports generated by an automated scanner with no demonstrated impact.
  • Missing hardening headers, cookie flags or version banners with no exploitable consequence.
  • Social engineering of our staff, physical access attempts, and denial of service testing of any kind.
  • A demo environment's test data. Every figure in a product recording or screenshot is demonstration data, not a real player.

What we ask of you

Report privately first. Send a description, the steps to reproduce it, and whatever shows the impact. If you include a proof of concept, keep it to the smallest one that demonstrates the problem.

Please do not access, modify or store data that is not your own. Please do not degrade the service for anybody else, and please do not disclose publicly until we have confirmed that a fix is out. If we disagree about timing, tell us why and we will work it out rather than go quiet on you.

We will not pursue legal action against a researcher who follows this policy in good faith.

What happens after you report

Five commitments rather than a workflow diagram, because what a researcher actually wants to know is whether a stranger will bother to answer.

We acknowledge a report within five working days and keep you updated until it is closed.

  1. A person reads it

    The address goes to people, not to a queue. You get a reply from somebody who can act on the report rather than an automated receipt.
  2. We try to reproduce it

    We follow your steps exactly as written. If we cannot reproduce the issue we tell you what we saw and ask, rather than closing the report quietly.
  3. We agree the severity in writing

    You get our assessment of the impact and the reasoning behind it. Where we disagree with yours we say why, and we are happy to be argued out of it.
  4. We fix it and tell you when

    You hear when a fix is out. If it is going to take longer than we said, you hear that before the date passes rather than after it.
  5. We credit you, if you want it

    Once an issue is closed you can be credited by whatever name you choose, or left out of it entirely. It is your call and we will not publish it before you answer.

Found something? Send it privately first.

Include the steps to reproduce it and whatever shows the impact. Keep a proof of concept to the smallest one that demonstrates the problem, and we will take it from there.

No bug bounty. Every report is read, answered and credited if you want credit.