Security Vulnerability Reporting
Guidelines for independent security researchers to responsibly discover, test, and disclose potential security vulnerabilities to the Skout AI Security Engineering Team.
Overview
At Skout AI, we take security seriously. We welcome the contributions of security researchers who help us identify and fix vulnerabilities in our platform. Responsible disclosure helps us protect our users and maintain the security, integrity, and privacy of our systems.
This document outlines our vulnerability disclosure program, including what systems are in scope, how to report vulnerabilities, and what you can expect when working with our security team.
We will not pursue legal action against researchers who follow our responsible disclosure policy. We work collaboratively with the security community to ensure all vulnerabilities are properly addressed before any public disclosure.
What's In Scope
The following systems and services are currently within the scope of our vulnerability disclosure program:
- skoutai.com and all subdomains operated by Skout AI
- Skout AI web application and platform infrastructure
- Skout AI API endpoints and services
- Mobile applications published by Skout AI
- Third-party integrations officially maintained by Skout AI
- Security configurations and cloud infrastructure
Out of Scope
The following activities and systems are not within the scope of our program. Reports involving these may not be eligible for acknowledgment or rewards:
- Third-party services not operated by Skout AI
- Social engineering attacks on Skout AI employees
- Physical security attacks on Skout AI facilities
- DDoS attacks, spamming, or brute-force attacks that disrupt service
- Issues requiring outdated browser exploitation
- Missing security headers that don't directly lead to a vulnerability
- Self-XSS that requires user interaction to execute
- CSRF on unauthenticated endpoints
Disclosure Process
Follow these steps when reporting a security vulnerability to our team:
Identify a potential security vulnerability in our systems. Ensure you only test against systems you own or have explicit permission to test.
Confirm the vulnerability is reproducible and not a false positive. Document all steps required to reproduce the issue.
Send a detailed report to our security team at security@skoutai.io. Include all technical details, proof-of-concept, and your contact information.
Work with our security team to validate and remediate the vulnerability. We'll keep you updated throughout the process.
Once the issue is fixed, we'll coordinate a public disclosure timeline. We typically publish acknowledgments for valid, responsibly disclosed vulnerabilities.
Reporting Guidelines
To help us investigate and remediate vulnerabilities quickly, please include the following information in your report:
- A clear description of the vulnerability and its potential impact
- Step-by-step reproduction steps including any affected URLs
- Screenshots or proof-of-concept code, if available
- Any tools or versions used during testing
- Your name and contact information (for follow-up)
- Whether you've discovered this vulnerability previously or reported it elsewhere
Never: Access or modify user data that doesn't belong to you, perform testing that could disrupt our services for other users, or attempt to exploit a vulnerability beyond what's necessary to prove its existence.
What to Expect
After submitting your report, here's what you can expect from our security team:
We'll acknowledge receipt of your report and begin our initial assessment.
Our team will reproduce and validate the vulnerability, assessing its severity.
We'll share our timeline for fixing the issue, typically 30-90 days depending on complexity.
Once fixed, we'll coordinate public disclosure and publish an acknowledgment.
Contact Our Security Team
To report a security vulnerability, or if you have any questions about our disclosure program, please contact our security engineering team directly.
Our security team prefers encrypted communication when possible. If you would like to send sensitive information, please ask for our PGP key in your initial email.