Skip to content
idleakcheck
SECURITY & PRIVACY, 2 MIN READ

Reporting a security issue.

How to send us a vulnerability report, what we ask of finders, and what to expect after you report.

If you've found a security issue in IDLeakCheck — authentication bypass, data leakage, injection, broken access control, anything — please tell us before disclosing publicly. We treat reports seriously and reply to every one.

How to report

Email security@idleakcheck.com with a description of the issue, reproduction steps, and any proof-of-concept payload. Include the URL or endpoint, the request body or parameters, the response, and any timestamp ranges that help us correlate logs.

If the issue is sensitive (active exploit, credential exposure), please don't send the details over an unencrypted channel — request a PGP key first.

What we ask

We don't operate a formal bug bounty program at this time. We do credit responsible reporters in our security disclosures if you'd like recognition. We ask that you give us a reasonable window to investigate and patch before any public disclosure — typically 90 days, sooner for low-risk issues, longer for issues that require coordinated disclosure with third parties.

TIPAvoid testing against real user accounts other than your own. Don't pivot through a finding to access data that isn't yours.

Out of scope

  • Denial of service attacks against our infrastructure
  • Volumetric scanning, brute-force attempts
  • Social engineering of our personnel or vendors
  • Self-XSS that requires the victim to paste arbitrary code into their own console
  • Findings on third-party services we don't control (Stripe, Postmark, Cloudflare — report directly to them)
Have a question this article didn’t answer? Contact support.