VDP // RESPONSIBLE DISCLOSURE

Security researchers welcome.

At OptOutScout, we believe real security requires outside eyes. We deeply appreciate the white-hat community and are committed to working with independent researchers to verify and patch vulnerabilities in our infrastructure.

Safe Harbor Statement

We consider activities conducted consistently with this policy to constitute "authorized" conduct under the Computer Fraud and Abuse Act (CFAA). We will not initiate legal action against you for bypassing security controls, provided you follow these guidelines.

In Scope

  • optoutscout.com & *.optoutscout.com
  • Auth bypass & hijacking
  • XSS & CSRF (Sensitive)
  • Database injection

Out of Scope

  • DDoS / Spam / Flooding
  • Social engineering & Phishing
  • Third-party infrastructure

Recognition & Appreciation

OptOutScout is a 100% self-funded project. Because we do not have venture capital backing, we do not currently offer financial bounties for bug reports.

However, we deeply respect the time and effort it takes to audit our systems. For any valid, critical vulnerability reported, we are happy to offer a spot in our Security Hall of Fame below, alongside complimentary lifetime access to our platform.

Submit a Report

Found something?

Please include reproduction steps and a PoC.

Security Hall of Fame

Radar Log // P1 Anomalies STATUS: SCANNING
> Searching for external validation... SYS_WAIT
_ List is currently empty. Be the first.
OptOutScout Boise, Idaho Built for Digital Sovereignty