We welcome security research conducted in good faith. If you believe you've found a security vulnerability, we want to hear from you.
Report vulnerabilities to:
security@anything.comWeb applications and APIs
Authentication and authorization systems
Data exposure or leakage vulnerabilities
Server-side vulnerabilities (injection, RCE, SSRF, etc.)
The following will be closed without response:
Email/DNS Configuration
Missing or misconfigured CAA records
SPF, DKIM, or DMARC issues
DNS zone transfer (unless demonstrating data exfiltration)
TLS/SSL
TLS version or cipher suite preferences
Certificate transparency issues
HSTS preload status
SSL/TLS best practice recommendations without demonstrable exploit
Security Headers
Missing Content-Security-Policy
Missing X-Frame-Options, X-Content-Type-Options, etc.
Clickjacking on pages without sensitive actions
Missing Referrer-Policy or Permissions-Policy
Low-Impact Issues
Self-XSS (requires victim to paste code into their own console)
Logout CSRF
Login/logout page clickjacking
Cookie flags on non-sensitive cookies
CORS misconfiguration without demonstrated impact
Open redirects without a chained attack
Rate limiting suggestions
Username/email enumeration via login or registration
Stack traces or verbose errors without sensitive data exposure
Scanner Output
Automated vulnerability scanner reports without manual verification
"Best practice" or "informational" severity findings
Reports consisting only of tool output (Nessus, Qualys, Burp, etc.)
Other Exclusions
Third-party services (report to them directly)
Social engineering attacks
Physical security
Denial of service (DoS/DDoS)
Reports must include all of the following or they will be closed:
Affected URL/Endpoint — Exact URL, API endpoint, or component
Vulnerability Type — e.g., SQL Injection, IDOR, Stored XSS, Auth Bypass
Concrete Impact — What can an attacker actually do? What data is exposed?
Step-by-Step Reproduction — Numbered steps we can follow to reproduce
Proof — HTTP requests/responses, screenshots, curl commands, or working PoC
We will acknowledge receipt within 5 business days
We will provide an initial assessment within 15 business days
We will not pursue legal action against researchers acting in good faith
We will credit researchers (if desired) when vulnerabilities are fixed
Do not access, modify, or delete data belonging to other users
Do not degrade service availability
Do not publicly disclose vulnerabilities before we have had reasonable time to fix them (90 days)
Only test against accounts you own or have explicit permission to test
We recognize researchers who report valid vulnerabilities. With your permission, we will publicly credit you when the vulnerability is fixed. We do not currently offer monetary rewards.
Questions? Contact us at security@anything.com