Contact
Send reports to security@siteguardrail.com. Include a concise description, affected SiteGuardrail URL or component, reproducible steps, impact, and the minimum redacted evidence needed to understand the issue.
In scope
- SiteGuardrail web pages and APIs operated for the service
- Unauthorised access to private scan reports or entitlement state
- Credential, token, payment, or personal-data exposure caused by SiteGuardrail
- SSRF, authorization, injection, or other security weaknesses in SiteGuardrail itself
Stop before harm
Do not access another person's report beyond the minimum needed to identify a control failure. Do not download third-party data, use a discovered credential, change or delete data, create persistence, disrupt availability, run denial-of-service testing, send automated high-volume traffic, or test Stripe and other providers outside SiteGuardrail's own integration boundary.
Handling a report
We will review good-faith reports as capacity permits, may ask for clarification, and will prioritise remediation based on evidence, exploitability, and impact. Please allow time to investigate before public disclosure. This page does not authorise testing of systems or data that SiteGuardrail does not own or control.