Security reporting
Last updated: 13 September 2026
Report a vulnerability
Report security issues, scanner bypasses, and high-confidence false-negative vectors to security@toolproof-scan.vercel.app. Include a concise reproduction, the affected URL or route, expected and actual behavior, and any safe proof of impact. The machine-readable policy is available at /.well-known/security.txt.
Scope
Reports are welcome for Toolproof's public website, API routes, scanner logic, response-signing flow, and vulnerabilities that could disclose data, bypass intended protections, or materially undermine a verdict. Scanner evasion and reproducible detection gaps are useful reports even when no system is compromised.
Please test safely
- Test only Toolproof or systems you own or are explicitly authorized to assess.
- Do not access other users' data, disrupt the Service, send high-volume traffic, or use social engineering.
- Do not submit real credentials, personal data, destructive payloads, or secrets in a report or scan target.
- Use a non-destructive proof of concept and stop once you have enough evidence to report the issue.
Security controls
Toolproof uses HTTPS, security response headers, a restrictive content security policy, and basic SSRF protections that reject known private and internal addresses before scanning. These controls reduce risk; they do not make the Service invulnerable. We do not publish a response-time commitment or bounty program at this time.
Disclosure
Please give us a reasonable opportunity to investigate and address a report before public disclosure. We will not ask you to expose secrets or continue a risky test. Do not publish details that would create an immediate, avoidable risk to users while a fix is being prepared.