Security
Vulnerability Disclosure Policy
We take the security of the people who use ScriptyPointer seriously. If you have found a vulnerability, we want to hear about it, and this page explains how to tell us and what we will do about it.
We do not operate a paid bug bounty program.
We do not offer money, swag, or other rewards for vulnerability reports. We are glad to credit researchers publicly for confirmed findings where they would like that. Please decide whether that is worth your time before you begin — we would rather be upfront than waste it.
Reporting a vulnerability
Email security@scriptypointer.com with “Security” in the subject line.
Please include, as far as you are able:
- The affected URL, endpoint, or feature.
- What the issue is and what an attacker could achieve with it.
- Clear steps to reproduce it — a description is fine, a video is welcome.
- Any accounts or test data you used, so we can clean them up.
Report in English where you can. Please do not open a public issue, post publicly, or contact our users about it.
What to expect from us
- We aim to acknowledge your report within 5 business days.
- We will tell you whether we have reproduced it, and roughly what we intend to do.
- We will let you know when it is fixed.
- We will credit you by name or handle if you want that, and leave you out of it if you do not.
ScriptyPointer is a small team. We will be honest with you about timelines rather than promising ones we cannot meet.
In scope
www.scriptypointer.comand its subpages.- Our public API, including the endpoints the website itself calls.
- Anything that exposes another user's data, moves or misdirects money, or lets someone act as a user they are not.
Out of scope
Reports limited to the following are unlikely to be actioned. This is not us dismissing them — it is us being clear about what we can use.
- Third-party services we rely on — Stripe, Checkr, Google, Vercel, and our email providers. Report those to them; they have their own programs.
- Missing security headers, cookie flags, or TLS configuration preferences without a demonstrated exploit.
- SPF, DKIM, or DMARC configuration findings.
- Clickjacking on pages with no state-changing action.
- Self-XSS, or issues requiring a fully compromised device or browser.
- Missing rate limits without a demonstrated impact.
- Raw output from an automated scanner with no working proof of concept.
- Version-disclosure banners and similar fingerprinting.
- Social engineering, phishing, or physical attacks against our staff or users.
- Denial of service, resource exhaustion, or volumetric testing of any kind.
Rules for testing
ScriptyPointer is a live marketplace. Real clients post real projects and real money sits in escrow against them. Testing that disrupts that harms people who have nothing to do with security research, so:
- Use your own test accounts. Do not access, modify, or delete data belonging to anyone else.
- If you do come across another user's data, stop, do not save or share it, and tell us what you saw so we can assess the exposure.
- Do not interfere with live projects, payments, escrow, or payouts.
- No denial of service, and no high-volume automated scanning.
- Do not social-engineer our users, our professionals, or our staff.
- Stop at the point you have proved the issue exists. Do not pivot deeper to see how far you can get.
- Give us a reasonable opportunity to fix it before telling anyone else.
Safe harbour
If you make a good-faith effort to follow this policy, we will treat your research as authorised. We will not pursue legal action against you, and we will not report you to law enforcement, for activity that stays within the rules above.
If a third party brings action against you for research you carried out in line with this policy, we will make clear that it was authorised.
This protection is ours to give and covers only our own systems. It cannot waive the rights of our users, our payment provider, or anyone else, and it does not apply to activity that breaks the rules above — in particular accessing other people's data, disrupting the service, or attaching a payment demand or disclosure deadline to a report.
Not a security issue?
For anything else — an account problem, a dispute, a bug that is not a vulnerability — please use our support page instead.
Machine-readable contact details: /.well-known/security.txt · Terms · Privacy