Skip to main content
HOME|TRUST & COMPLIANCE
COORDINATED DISCLOSURE

Vulnerability Disclosure Policy

SubdomainWatch values the security community. We encourage responsible reporting of potential vulnerabilities across our services and pledge to work constructively with researchers.

Reporting Channel

Please submit all security vulnerability reports directly to:

Include detailed reproduction steps, potential impact, and relevant code or HTTP payloads. Please do not publish or discuss findings publicly until coordinated remediation is complete.

Scope of Assessment

In-Scope Assets
  • subdomainwatch.com
  • *.subdomainwatch.com web apps
  • Public scanner API endpoints (/api/probe, /api/tools/*)
  • Console authentication & tenant isolation logic
Out-of-Scope
  • Volumetric Denial of Service (DoS/DDoS) attacks
  • Social engineering, phishing, or physical attacks
  • Third-party cloud infrastructure (Fly.io, Supabase, Resend)
  • Attacks against monitored customer domains

Safe Harbor Commitment

If you conduct security research and report vulnerabilities in good faith accordance with this policy, we will consider your activities authorized, will not initiate legal action against you, and will work cooperatively to validate and address the issue promptly.

Initial Acknowledgement: Within 48 business hours.
Status Updates: Transparent communication through remediation.
Public Recognition: Researchers adhering to this policy will be credited upon mutual agreement.
SubdomainWatch Trust & Safety
RFC 9116 Coordinated Disclosure • security@subdomainwatch.com