← IPScanner.Pro

COORDINATED DISCLOSURE

Report a vulnerability

Email security@ipscanner.pro with what you found and how to reproduce it. Report early rather than not at all: an unclear suspicion is worth more to us than silence. The same address is published in machine-readable form at /.well-known/security.txt.

Write to security@ipscanner.pro

What we ask of you

What we will do

We do not publish a response-time commitment, because one we cannot keep would be worth nothing. What we will not do is leave a report unanswered.

In scope

Out of scope

What to include in a report

The machine-readable version

This channel is also published under RFC 9116 at /.well-known/security.txt, which names the same address and carries an expiry of 2027-09-11 so that a stale file is visibly stale rather than quietly trusted.

Common questions

Is there a bug bounty?

No, and we would rather say so plainly than let you find out after the work. There is no payment scheme today. Credit in the fix notes is offered if you want it, and declined gladly if you do not.

Can I publish what I found?

Please give us a reasonable window to fix it first — ninety days is the norm we work to, sooner when the fix is simple. If a fix is taking longer than that, we would rather agree a date with you than go quiet.

Do you have a PGP key?

Not published yet. If your report is sensitive enough that plain email worries you, say so in a first message without the detail and we will agree a channel before you send anything further.

I am not sure it is a real problem. Should I still write?

Yes. Deciding whether something is a vulnerability is our job, not a filter you have to pass first. An uncertain report costs us a few minutes; an unreported one can cost a user their network.

Not a security problem — just something broken, confusing, or wrong on a page? That goes to support, and it is just as welcome.