Skip to content

Report a vulnerability in SiteGuardia

If you have found a security problem in this service, this page is how to tell us. It is about SiteGuardia itself. If you are looking for the rules about scanning a website with SiteGuardia, those are in Responsible Scanning.

Where to send it

By email. There is no form, because a form is one more thing that can be broken by the thing you are reporting.

help@siteguardia.com

There is no reward programme. Reports are read and answered by a person, and no response time is committed to yet.

The same address is published in machine-readable form, in the format RFC 9116 defines: /.well-known/security.txt

What is in scope

The SiteGuardia web application, its API, the report links it issues, and the infrastructure serving them, at the domain named on this page.

  • Anything that would let one visitor read another visitor's report.
  • Anything that would let a scan be pointed at a target the requester has no authorisation over.
  • Anything that would let a scanner reach a network it is isolated from.
  • Authentication, rate limiting and quota bypasses.
  • Injection, deserialization or template flaws in the application or the PDF renderer.

What is out of scope

Not because these do not matter, but because a report about them tells us something we already know or something we cannot act on.

  • Findings produced by SiteGuardia about somebody else's website. Those belong to the site's owner, not to us.
  • Denial of service, volumetric testing and anything that degrades the service for other visitors.
  • Social engineering of anyone involved, and physical access.
  • Reports generated by an automated scanner with no evidence that the issue is reachable or exploitable.
  • Missing headers or configuration on marketing pages with no demonstrated impact.

What we ask

  • Test against your own account and your own report links, never somebody else's.
  • Stop at the point where you have demonstrated the problem. Do not read, alter or keep data that is not yours.
  • Give us a reasonable period to fix it before publishing.
  • Send enough detail to reproduce: the request, the response, and what you expected instead.

What happens next

  • We acknowledge receipt and tell you whether we can reproduce it.
  • We tell you what we intend to do and roughly when.
  • We tell you when it is fixed, and we credit you if you want to be credited.

Those are our intentions, not a service-level commitment. A commitment with a number in it needs someone who has agreed to be on the other end of it, and SiteGuardia has not launched.

Good-faith research

We will not pursue legal action over research that follows the rules above, stays within scope and does not damage the service or its users. This is a statement of intent by the operator, not a legal safe harbour: it cannot bind a third party, and it does not override the law where you are.

Related