Security Policy
Last updated: 2026-07-30
1. Reporting a vulnerability
We appreciate reports from security researchers and take them seriously. If you believe you've found a security vulnerability in ProbeScope or on this website, please email security@probescope.net.
Please include as much detail as you can: steps to reproduce, the affected component or URL, and the potential impact. This helps us verify and address the issue faster.
Please do not publicly disclose the issue before we've had a chance to respond.
2. Scope
This policy covers:
- The ProbeScope application (the binary you download and run)
- This website, probescope.net
The following are out of scope:
- Denial-of-service testing
- Social engineering or phishing attempts against our team or users
- Physical attacks against our infrastructure or offices
- Automated scanning that generates significant traffic without prior coordination
3. Our commitment
When you report a vulnerability to us in good faith, we commit to:
- Acknowledging your report within 3 working days
- Keeping you informed as we investigate and address the issue
- Crediting you on our Hall of Fame page, if you'd like
4. Safe harbor
We will not pursue legal action against researchers who discover and report vulnerabilities in good faith, in accordance with this policy. This includes testing performed without causing harm to our users, degrading our services, or accessing data beyond what's necessary to demonstrate the vulnerability.
5. Coordinated disclosure
We ask that you give us 90 days from your initial report to investigate and address the issue before any public disclosure. We'll keep you updated on our progress throughout this period, and are happy to discuss timing if a fix needs more time.
6. Contact
Reach us at security@probescope.net. Our machine-readable security policy is also available at /.well-known/security.txt.