← Back to security

Vulnerability Disclosure

How to report a vulnerability, what is in scope, and what you can expect from us.

Reporting a vulnerability

Report it through our contact form with enough detail to reproduce the issue. We respond within 48 hours.

Report it via our contact form with a clear description of the issue, steps to reproduce, and your assessment of impact. You can encrypt your report using our PGP key:

PGP Fingerprint

981E AE52 7918 5946 D5D0 A595 34CC 6F8A F0D2 8039

Scope

Our web app, API, Chrome extension, and anything under amibeingpwned.com. Third-party services we use are not in scope.

In scope

  • amibeingpwned.com and all subdomains - authentication, API endpoints, dashboard, and any customer-facing surface
  • The Am I Being Pwned? Chrome extension - data handling, permissions usage, communication with our backend
  • The public API - authentication bypass, authorisation flaws, data exposure across organisation boundaries
  • Our finding reports - if you believe we have published an inaccurate or misleading finding about an extension

Out of scope

  • Third-party services we use (Cloudflare, Google, etc.) - report those directly to the vendor
  • Denial of service attacks or volumetric testing of any kind - please do not attempt to take down or degrade our service during research
  • Social engineering of our team or customers
  • Physical security
  • Issues requiring unlikely user interaction or that only affect outdated browsers
  • Missing security headers or TLS configuration issues without a demonstrated impact
  • SPF, DMARC, and DKIM configuration on domains we do not actively send email from
  • Rate limiting issues that do not result in meaningful data exposure
  • Theoretical vulnerabilities without a working proof of concept

Testing guidelines

Use a test account, do not DoS us, do not touch other users' data, and do not run automated scanners at scale against our infrastructure.

  • Do not perform DoS or load testing. We run a real production service with real customers. Any testing that affects availability or performance for others is outside this policy and may result in your IP being blocked.
  • Do not run automated scanners at scale. Aggressive crawling or fuzzing tools that generate significant load are not permitted. Test manually or with targeted, low-volume tooling.
  • Use a test account you own. Create a free account for your research. Do not test against other users' accounts or data, even to demonstrate a vulnerability.
  • Do not access, modify, or exfiltrate data that is not yours. If you discover a vulnerability that would allow access to other users' data, demonstrate it against your own account and stop.
  • Do not disrupt extension findings. If your research involves extensions we have analysed, do not attempt to manipulate our scoring pipeline or inject findings.

Response timeline

48-hour acknowledgement, 7-day triage, 30-day target fix for critical issues. We will keep you updated throughout.

  • Within 48 hours - acknowledgement that we have received your report
  • Within 7 days - initial triage, severity assessment, and confirmation of whether the issue is in scope
  • Within 30 days for critical issues - target for a fix or mitigation to be deployed. We will let you know if a longer timeline is needed and why.
  • Within 90 days for complex issues - for vulnerabilities requiring significant architectural changes, we aim to resolve within 90 days. We will coordinate a disclosure timeline with you.

We will keep you updated at each stage. If you have not heard from us within 48 hours, follow up via our contact form.

Rewards and recognition

We do not currently run a paid bug bounty programme. We do offer public credit and, for significant findings, direct recognition from the team.

We do not currently operate a paid bug bounty programme. If you are looking for financial rewards, we are not the right target right now and we would rather you knew that upfront.

For valid, in-scope findings we offer:

  • Public credit in any disclosure or post-mortem, if you want it
  • A direct thank-you from the team for significant findings
  • For critical findings that prevent real harm to our customers, we will consider other forms of recognition on a case-by-case basis - reach out and talk to us

Safe harbor

We will not pursue legal action against researchers who act in good faith under this policy.

We consider security research conducted under this policy to be authorised. We will not pursue civil or criminal legal action against researchers who:

  • Follow the testing guidelines above
  • Report findings to us before public disclosure and give us reasonable time to respond
  • Do not access, modify, or destroy data belonging to other users
  • Do not attempt to extort us or our customers

If at any point you are uncertain whether what you are doing is within scope, stop and email us before continuing.