Security Policy

ScopeHunter — professional & trust network for security practitioners

ScopeHunter is built for security professionals, which means we hold ourselves to a higher bar than "trust us." This page describes how we handle vulnerability reports, what we actually do to protect your account and data, and where our current gaps are — stated plainly rather than glossed over.

Reporting a vulnerability

If you believe you've found a security issue in ScopeHunter, we want to hear about it before anyone else does. Email security@scopehunter.io with as much detail as you can provide: the affected endpoint or feature, steps to reproduce, and the impact you believe it has. Please do not open a public GitHub issue for anything that hasn't already been fixed.

What to expect

Safe harbor

We will not pursue legal action against, or report to law enforcement, anyone who makes a good-faith effort to comply with this policy. Good faith means:

Scope

In scope: scopehunter.io and its subdomains, and the API/auth services they talk to.

Out of scope:

How we protect your account

How we protect your data

Where we're not there yet

In the interest of not overstating our posture: there's no dedicated WAF in front of the site yet — nginx-level rate limiting on the login endpoint covers brute-force attempts, but a WAF would add broader protection against a wider range of request-level attacks — and this is a young platform that hasn't yet been through an independent third-party security audit. None of this is hidden from anyone who reads our source — ScopeHunter's backend and infrastructure automation are open about their current state by design.

Last updated: 2026-08-09. This policy is also published in machine-readable form at /.well-known/security.txt (RFC 9116).