Responsible disclosure

Report a security issue affecting SiteGuardrail

How to report a vulnerability affecting SiteGuardrail safely, including scope, evidence, prohibited testing, and the security contact.

Contact
security@siteguardrail.com
Evidence
Minimal and redacted
Third-party data
Do not access

Contact

Send reports to security@siteguardrail.com. Include a concise description, affected SiteGuardrail URL or component, reproducible steps, impact, and the minimum redacted evidence needed to understand the issue.

In scope

  • SiteGuardrail web pages and APIs operated for the service
  • Unauthorised access to private scan reports or entitlement state
  • Credential, token, payment, or personal-data exposure caused by SiteGuardrail
  • SSRF, authorization, injection, or other security weaknesses in SiteGuardrail itself

Stop before harm

Do not access another person's report beyond the minimum needed to identify a control failure. Do not download third-party data, use a discovered credential, change or delete data, create persistence, disrupt availability, run denial-of-service testing, send automated high-volume traffic, or test Stripe and other providers outside SiteGuardrail's own integration boundary.

Handling a report

We will review good-faith reports as capacity permits, may ask for clarification, and will prioritise remediation based on evidence, exploitability, and impact. Please allow time to investigate before public disclosure. This page does not authorise testing of systems or data that SiteGuardrail does not own or control.