Report a vulnerability in SiteGuardia
If you have found a security problem in this service, this page is how to tell us. It is about SiteGuardia itself. If you are looking for the rules about scanning a website with SiteGuardia, those are in Responsible Scanning.
Where to send it
By email. There is no form, because a form is one more thing that can be broken by the thing you are reporting.
There is no reward programme. Reports are read and answered by a person, and no response time is committed to yet.
The same address is published in machine-readable form, in the format RFC 9116 defines: /.well-known/security.txt
What is in scope
The SiteGuardia web application, its API, the report links it issues, and the infrastructure serving them, at the domain named on this page.
- Anything that would let one visitor read another visitor's report.
- Anything that would let a scan be pointed at a target the requester has no authorisation over.
- Anything that would let a scanner reach a network it is isolated from.
- Authentication, rate limiting and quota bypasses.
- Injection, deserialization or template flaws in the application or the PDF renderer.
What is out of scope
Not because these do not matter, but because a report about them tells us something we already know or something we cannot act on.
- Findings produced by SiteGuardia about somebody else's website. Those belong to the site's owner, not to us.
- Denial of service, volumetric testing and anything that degrades the service for other visitors.
- Social engineering of anyone involved, and physical access.
- Reports generated by an automated scanner with no evidence that the issue is reachable or exploitable.
- Missing headers or configuration on marketing pages with no demonstrated impact.
What we ask
- Test against your own account and your own report links, never somebody else's.
- Stop at the point where you have demonstrated the problem. Do not read, alter or keep data that is not yours.
- Give us a reasonable period to fix it before publishing.
- Send enough detail to reproduce: the request, the response, and what you expected instead.
What happens next
- We acknowledge receipt and tell you whether we can reproduce it.
- We tell you what we intend to do and roughly when.
- We tell you when it is fixed, and we credit you if you want to be credited.
Those are our intentions, not a service-level commitment. A commitment with a number in it needs someone who has agreed to be on the other end of it, and SiteGuardia has not launched.
Good-faith research
We will not pursue legal action over research that follows the rules above, stays within scope and does not damage the service or its users. This is a statement of intent by the operator, not a legal safe harbour: it cannot bind a third party, and it does not override the law where you are.