stackwitness

Security and vulnerability disclosure

We want to hear from security researchers. If you believe you have found a vulnerability in a service we operate, please report it to us privately using the details below, and give us reasonable time to remediate before any public disclosure.

How to report

Email hello@stackwitness.com with the subject line "Security report". Please include:

A machine-readable pointer to this policy is published at /.well-known/security.txt.

Safe harbor

We consider good-faith security research conducted in line with this policy to be authorized. For research that stays within the scope below, acts in good faith, avoids privacy violations and service disruption, and gives us a reasonable chance to remediate before disclosure, we will not pursue legal action against you or ask law enforcement to do so. If a third party brings legal action against you for activity conducted under this policy, we will make it known that your actions were authorized. This is not a waiver of any rights of third parties, and it does not authorize activity against systems we do not operate.

In scope

Production services that we operate under the stackwitness.com domain, including this site and the application at app.stackwitness.com.

Out of scope

What to expect

We aim to acknowledge reports within a few business days and to keep you informed as we investigate. We practice coordinated disclosure: please keep reports confidential until we have had a reasonable opportunity to remediate. With your permission, we are glad to credit you for a valid report.

No bug bounty

We do not offer a monetary bounty at this time. We deeply appreciate responsible reports and will thank and credit researchers with their consent.

Governing law

This policy is governed by the laws of the State of Illinois, USA, consistent with our Terms.

Contact

O'Shea & Sons, LLC
hello@stackwitness.com