Vulnerability Disclosure Policy (VDP)
Last updated: 26 July 2026
1. Introduction
Scott Labz (“we” or “us”) is committed to ensuring the security of our systems and the privacy of our users. We appreciate the security community's efforts in identifying vulnerabilities and helping us maintain a high standard of digital safety.
2. Guidelines
Under this policy, we ask that you:
- Notify us as soon as possible after discovering a real or potential security issue.
- Make every effort to avoid privacy violations, degradation of user experience, disruption to production systems, and destruction of data.
- Only use exploits to the extent necessary to confirm a vulnerability's presence.
- Do not download or store any confidential user data beyond what is strictly required to prove vulnerability existence.
- Provide us a reasonable amount of time to resolve the issue before publicly disclosing it.
3. Safe Harbor
When research is conducted in accordance with this policy, we consider your security research to be authorized. We will not initiate legal action against you regarding research conducted under these guidelines.
4. Reporting a Vulnerability
If you believe you have found a security vulnerability, please submit your report directly to [email protected].
- Details to Include: Description of the location and potential impact of the vulnerability, along with step-by-step instructions or scripts to reproduce it.
cott Labz