SWORT welcomes good-faith reports of security vulnerabilities affecting our website. This page is our vulnerability disclosure policy. It is not a description of our security architecture, and it does not authorize testing of systems we do not control.
1. Purpose
This policy explains how to report a suspected vulnerability in SWORT web systems, what testing is and is not authorized, and what you can expect from us.
2. How to report
Send reports to [email protected] with "Security" in the subject line.
A useful report includes: the affected URL or endpoint, a clear description of the issue, the steps needed to reproduce it, the minimum evidence required to demonstrate impact, and how we can contact you. Please send one issue per report where practical.
For an issue you believe is being actively exploited, mark it "Urgent" in the subject line and describe the observed impact first.
3. Systems in scope
swort.netand its public subpages;- SWORT-operated API endpoints served under
swort.net/api/; - Files and configuration published by SWORT on this domain.
4. Systems out of scope
- Any system, product, or network not operated by SWORT;
- Customer systems, vehicles, or hardware;
- Employee or contractor personal accounts and devices;
- Physical facilities;
- Findings that require an already-compromised device or browser;
- Reports based solely on automated scanner output without demonstrated impact;
- Missing best-practice headers or configuration with no demonstrated security impact;
- Social-media or brand-impersonation accounts, which should be reported by email but are not vulnerabilities in this website.
5. Third-party platforms
This website depends on third-party providers described in our Privacy Policy, including hosting, form handling, scheduling, font delivery, and advertising technologies.
This policy does not authorize you to test, probe, or attack any third-party provider. Report vulnerabilities in a third-party service directly to that provider under its own disclosure program.
6. Rules for good-faith research
We ask that you:
- Act in good faith and avoid privacy violations, service degradation, and data destruction;
- Use only your own accounts and test data;
- Stop as soon as you have confirmed a vulnerability, and collect only the minimum evidence needed to demonstrate it;
- Do not access, copy, modify, or retain data that is not yours;
- Give us a reasonable opportunity to remediate before any public disclosure;
- Comply with applicable law.
7. Prohibited testing
The following are not authorized under this policy:
- Denial-of-service, stress, load, or volumetric testing;
- Automated scanning that degrades service or generates excessive traffic;
- Social engineering, phishing, or pretexting of any person;
- Targeting SWORT employees, contractors, customers, or their accounts;
- Physical testing of any facility, and any attempt at physical access;
- Destructive testing, including deleting, corrupting, or altering data;
- Installing malware, backdoors, or any persistence mechanism;
- Accessing, exfiltrating, or retaining personal, customer, or proprietary data;
- Pivoting to other systems or networks.
8. Handling personal or customer data
If you encounter personal information, customer information, or anything that appears sensitive or controlled, stop immediately, do not download or retain it, and tell us what you found in general terms. Do not include the data itself in your report unless we ask, and do not share it with anyone else.
9. Coordinated disclosure
Please do not publicly disclose a vulnerability before we have remediated it or before we have agreed a disclosure date with you. We are happy to credit reporters who wish to be named once an issue is resolved.
10. What to expect
SWORT aims to acknowledge legitimate security reports within a reasonable period based on severity and available resources. We are a small engineering team and we do not guarantee a fixed response or remediation deadline. We will tell you if we need more information, and we will let you know when we believe an issue is resolved.
11. No bounty
SWORT does not currently operate a paid bug-bounty program, and submitting a report does not entitle you to payment. We appreciate responsible reports and will acknowledge them.
12. Changes to this policy
We may update this policy. The effective date and last-updated date appear at the top of this page. A machine-readable summary is published at /.well-known/security.txt.
Return to swort.net