Editorial draft, safe-harbour pending counsel review
Security and Vulnerability Disclosure
We welcome good-faith reports of security vulnerabilities in Security Checklist properties. Email security@securitycheckli.st. Formal safe-harbour and SLA language is pending counsel review.
Purpose
This page and /.well-known/security.txt give researchers a clear contact for issues that could affect confidentiality, integrity, or availability of our site, tools, or affiliate redirect paths.
It is not a bug bounty program announcement. Reward availability is pending verification and is not claimed here.
- Provide a public reporting channel
- Define in-scope systems at a high level
- Avoid requesting exploit weaponization against third parties
Policy
Please report vulnerabilities privately before public disclosure when feasible. Do not access data that is not yours, do not disrupt production for proof, and do not social-engineer our users.
Safe-harbour assurances for good-faith research are intended but must be reviewed by counsel before you rely on them as a legal commitment.
- Contact: mailto:security@securitycheckli.st
- Preferred languages: en (see security.txt)
- No public dump of user assessment answers
Process
Include the affected URL or component, a clear description of impact, and steps to reproduce that a defender can follow. Attach PoC only as needed for our own systems, do not include exploit packs aimed at third-party products we review.
We aim to acknowledge reports; specific response-time commitments are unpublished pending verification, listed in the verification register.
- In scope (intended): securitycheckli.st web app, /go/ redirector, assessment UIs
- Out of scope (examples): attacks on vendor products we write about, physical offices not yet published
- Do not send passwords or identity documents in reports
Accountability
Confirmed issues should be fixed or mitigated with documentation appropriate to severity. Public credit is optional and only with researcher consent, process not yet published.
Application security controls we intend to maintain include validation, CSRF protection, secure headers, rate limits, and dependency scanning (see internal security docs).
- security.txt Canonical: https://securitycheckli.st/.well-known/security.txt
- Policy URL in security.txt points here
- Privacy questions that are not vulns: /privacy/ and /contact/
Contact or escalation
Email security@securitycheckli.st. For non-security editorial issues, use /contact/ once the general inbox is verified.
- Contact page: /contact/
- Privacy: /privacy/
- Terms: /terms/
Limitations
- Safe-harbour and bounty statements are not finalized pending counsel review.
- Response SLAs are not guaranteed on this draft.
- This page does not authorize testing of third-party vendor products listed in reviews.
Expert guides & insights
Related pages
Trust, tools, and category hubs that connect to this policy.
Want launch updates?
The email newsletter is not running yet. Use Contact if you want a human reply when it opens. No fake signup form.
