Skip to main content

New in August: Password manager research and finders updated Read more

Independent reviews. Real tests. Smarter security decisions.

SecurityChecklist

Security and Vulnerability Disclosure

Report good-faith security issues affecting SecurityCheckli.st systems, tools and deal-link paths.

Coordinated disclosure, not a bug bounty

Email security@securitycheckli.st with the affected URL or component, impact and steps to reproduce. This channel is not a published bounty programme and does not promise an SLA.

How to report

Email security@securitycheckli.st. Include the affected URL or component, a clear description of impact, and plain-text steps to reproduce. Attach a minimal proof of concept only when needed for our own systems.

Do not send passwords, MFA codes, identity documents, banking data or exploit packs aimed at third-party vendors we review. Prefer coordinated private disclosure before public discussion when feasible.

Canonical researcher contact also appears at /.well-known/security.txt.

In scope

Issues that could affect confidentiality, integrity or availability of SecurityCheckli.st first-party properties, including the public site, assessment and finder tools, and affiliate deal-link redirect paths we operate.

  • Cross-site scripting or injection on first-party pages
  • Open redirects that bypass deal-link allowlists
  • CSRF gaps on state-changing flows we operate
  • Unexpected exposure of assessment answer payloads we should not retain

Out of scope

  • Attacks on third-party vendor products featured in reviews (report those to the vendor programme)
  • Denial-of-service or load testing without prior arrangement
  • Social engineering of staff or readers
  • Physical security of offices
  • Non-security privacy or editorial questions (use Privacy or Contact)

What to expect

We review reports as capacity allows. Acknowledgement and fix timelines vary; no SLA is published here. This is not a bug bounty and we do not publish a reward schedule. Public credit is optional and only with researcher consent.

A vulnerability report cannot be traded for a product score, affiliate placement or invented testing claim. Editorial independence still applies.

Controls we maintain

Controls include input validation, CSRF protection, secure headers, rate limits and dependency scanning where applicable. Assessment tools are designed to avoid collecting passwords, MFA codes, identity documents and full payment data. Affiliate clicks use first-party deal-link allowlists.

Other channels

Editorial and general mail: intel@securitycheckli.st via Contact. Corrections to published claims: Corrections.

Public operator identity: SecurityChecklist; +1 888 437 8441; One World Trade Center, 285 Fulton Street, 85th Floor, Suite 8500, New York, NY 10007, United States. See About.

Limitations

  • This page is operational disclosure guidance, not legal advice or a formal safe-harbour contract.
  • It does not authorise testing of third-party products listed in reviews.
  • It is not a product scorecard or shopping shortlist.

If you came for personal or business security research

Start with the Personal Security Checkup or browse tools, consumer hubs (VPN, antivirus, password managers, data privacy), Business Security or SecShield.

Need a practical security plan instead?

Start with free controls and a short checkup, then open category research.

Page information & sources Updated 2026-08-17

About this page

Report security issues affecting SecurityCheckli.st to security@securitycheckli.st. Coordinated disclosure guidance, scope, and contact details for researchers.

Methodology

Editorial responsibility

Published by SecurityChecklist editorial

Editorial policy

Publication history

First published:

Last updated:

Corrections

Request a correction

Commercial disclosure

Some product links may be commercial. Affiliate relationships never set rankings. See the affiliate disclosure.