Vulnerability Disclosure Policy

We welcome security research conducted in good faith. If you believe you've found a security vulnerability, we want to hear from you.

Report vulnerabilities to:

security@anything.com

In Scope

  • Web applications and APIs

  • Authentication and authorization systems

  • Data exposure or leakage vulnerabilities

  • Server-side vulnerabilities (injection, RCE, SSRF, etc.)

Out of Scope (Will Not Be Triaged)

The following will be closed without response:

Email/DNS Configuration

  • Missing or misconfigured CAA records

  • SPF, DKIM, or DMARC issues

  • DNS zone transfer (unless demonstrating data exfiltration)

TLS/SSL

  • TLS version or cipher suite preferences

  • Certificate transparency issues

  • HSTS preload status

  • SSL/TLS best practice recommendations without demonstrable exploit

Security Headers

  • Missing Content-Security-Policy

  • Missing X-Frame-Options, X-Content-Type-Options, etc.

  • Clickjacking on pages without sensitive actions

  • Missing Referrer-Policy or Permissions-Policy

Low-Impact Issues

  • Self-XSS (requires victim to paste code into their own console)

  • Logout CSRF

  • Login/logout page clickjacking

  • Cookie flags on non-sensitive cookies

  • CORS misconfiguration without demonstrated impact

  • Open redirects without a chained attack

  • Rate limiting suggestions

  • Username/email enumeration via login or registration

  • Stack traces or verbose errors without sensitive data exposure

Scanner Output

  • Automated vulnerability scanner reports without manual verification

  • "Best practice" or "informational" severity findings

  • Reports consisting only of tool output (Nessus, Qualys, Burp, etc.)

Other Exclusions

  • Third-party services (report to them directly)

  • Social engineering attacks

  • Physical security

  • Denial of service (DoS/DDoS)

Submission Requirements

Reports must include all of the following or they will be closed:

  • Affected URL/Endpoint — Exact URL, API endpoint, or component

  • Vulnerability Type — e.g., SQL Injection, IDOR, Stored XSS, Auth Bypass

  • Concrete Impact — What can an attacker actually do? What data is exposed?

  • Step-by-Step Reproduction — Numbered steps we can follow to reproduce

  • Proof — HTTP requests/responses, screenshots, curl commands, or working PoC

Our Commitment

  • We will acknowledge receipt within 5 business days

  • We will provide an initial assessment within 15 business days

  • We will not pursue legal action against researchers acting in good faith

  • We will credit researchers (if desired) when vulnerabilities are fixed

Researcher Expectations

  • Do not access, modify, or delete data belonging to other users

  • Do not degrade service availability

  • Do not publicly disclose vulnerabilities before we have had reasonable time to fix them (90 days)

  • Only test against accounts you own or have explicit permission to test

Recognition

We recognize researchers who report valid vulnerabilities. With your permission, we will publicly credit you when the vulnerability is fixed. We do not currently offer monetary rewards.

Questions? Contact us at security@anything.com