We run a security product, so we hold ourselves to the same standard we hold everyone else to. If you find a vulnerability in Dr. Security itself, we want to hear about it, and we won't come after you for telling us in good faith.
This policy covers getdrsecurity.com and its API. It does not cover the third-party sites our scans report on, so please disclose those directly to their owners.
Email [email protected] with steps to reproduce, impact, and any evidence. Please don't include real user data in your report.
We acknowledge new reports within 2 business days and share our assessment once we've reproduced the issue.
We keep you updated as we work on a fix, and if you're okay with it, we credit you publicly once it ships.
We won't pursue legal action against anyone who reports a vulnerability in good faith, avoids privacy violations and service disruption, and gives us a reasonable window to fix the issue before any public disclosure. This mirrors how our own scans treat the sites we check: passive, non-destructive, and disclosed responsibly.