Coordinated vulnerability disclosure policy

How to report a security issue with this site, what we ask of you while you look, and what we undertake in return.

Report it here

[email protected]

Read the rest before you start testing — the scope is narrow and a few things are explicitly out of it.

Scope

evulnable.com and www.evulnable.com, and the exports and files they serve. Nothing else is in scope: the third-party feeds this site reads from — CISA, FIRST, Microsoft, NIST and the vendor advisory sources named on the Methodology page — belong to their own operators and have their own disclosure channels.

How to report

Email [email protected].

Include enough to reproduce the finding: the URL, the request, and what you saw. A short proof of concept is welcome. If a report contains data belonging to someone else, say so and do not include the data itself.

What we ask of you

Test only against your own uploads and your own domains. Do not run scans that degrade the service for other people, do not attempt to access or modify anyone else's analysis or scan results, and do not publish a finding before it has been fixed or before we have agreed a date with you.

What we undertake

We will acknowledge a report and tell you whether we consider it a vulnerability. We will not pursue legal action over research conducted in good faith within this policy, and we will credit you when a finding is fixed if you would like to be credited.

What this is not

There is no bug bounty and no payment. There is no guaranteed response time; this site is run by one person.

Out of scope

Reports generated solely by an automated scanner with no demonstrated impact. Missing headers or configuration weaknesses with no exploitable consequence. Findings that require a compromised device, a malicious browser extension, or physical access. Denial of service through sheer volume of requests.

For automated tooling

The same policy is served as plain text at /security-policy.txt, which is what security.txt points at. Both are generated from this page's text, so they cannot disagree.

If you think the site is handling data differently from what the privacy page says, that is a security report and will be treated as one.