COORDINATED DISCLOSURE
Vulnerability Disclosure Policy
SubdomainWatch values the security community. We encourage responsible reporting of potential vulnerabilities across our services and pledge to work constructively with researchers.
Reporting Channel
Please submit all security vulnerability reports directly to:
Include detailed reproduction steps, potential impact, and relevant code or HTTP payloads. Please do not publish or discuss findings publicly until coordinated remediation is complete.
Scope of Assessment
In-Scope Assets
subdomainwatch.com*.subdomainwatch.comweb apps- Public scanner API endpoints (
/api/probe,/api/tools/*) - Console authentication & tenant isolation logic
Out-of-Scope
- Volumetric Denial of Service (DoS/DDoS) attacks
- Social engineering, phishing, or physical attacks
- Third-party cloud infrastructure (Fly.io, Supabase, Resend)
- Attacks against monitored customer domains
Safe Harbor Commitment
If you conduct security research and report vulnerabilities in good faith accordance with this policy, we will consider your activities authorized, will not initiate legal action against you, and will work cooperatively to validate and address the issue promptly.
• Initial Acknowledgement: Within 48 business hours.
• Status Updates: Transparent communication through remediation.
• Public Recognition: Researchers adhering to this policy will be credited upon mutual agreement.