Skout AI Logo
SKOUT TRUST — VULNERABILITY DISCLOSURE

Security Vulnerability Reporting

Guidelines for independent security researchers to responsibly discover, test, and disclose potential security vulnerabilities to the Skout AI Security Engineering Team.

Overview

At Skout AI, we take security seriously. We welcome the contributions of security researchers who help us identify and fix vulnerabilities in our platform. Responsible disclosure helps us protect our users and maintain the security, integrity, and privacy of our systems.

This document outlines our vulnerability disclosure program, including what systems are in scope, how to report vulnerabilities, and what you can expect when working with our security team.

Our Commitment to Researchers

We will not pursue legal action against researchers who follow our responsible disclosure policy. We work collaboratively with the security community to ensure all vulnerabilities are properly addressed before any public disclosure.

What's In Scope

The following systems and services are currently within the scope of our vulnerability disclosure program:

  • skoutai.com and all subdomains operated by Skout AI
  • Skout AI web application and platform infrastructure
  • Skout AI API endpoints and services
  • Mobile applications published by Skout AI
  • Third-party integrations officially maintained by Skout AI
  • Security configurations and cloud infrastructure

Out of Scope

The following activities and systems are not within the scope of our program. Reports involving these may not be eligible for acknowledgment or rewards:

  • Third-party services not operated by Skout AI
  • Social engineering attacks on Skout AI employees
  • Physical security attacks on Skout AI facilities
  • DDoS attacks, spamming, or brute-force attacks that disrupt service
  • Issues requiring outdated browser exploitation
  • Missing security headers that don't directly lead to a vulnerability
  • Self-XSS that requires user interaction to execute
  • CSRF on unauthenticated endpoints

Disclosure Process

Follow these steps when reporting a security vulnerability to our team:

1. Discover

Identify a potential security vulnerability in our systems. Ensure you only test against systems you own or have explicit permission to test.

2. Verify

Confirm the vulnerability is reproducible and not a false positive. Document all steps required to reproduce the issue.

3. Report

Send a detailed report to our security team at security@skoutai.io. Include all technical details, proof-of-concept, and your contact information.

4. Collaborate

Work with our security team to validate and remediate the vulnerability. We'll keep you updated throughout the process.

5. Resolve

Once the issue is fixed, we'll coordinate a public disclosure timeline. We typically publish acknowledgments for valid, responsibly disclosed vulnerabilities.

Reporting Guidelines

To help us investigate and remediate vulnerabilities quickly, please include the following information in your report:

  • A clear description of the vulnerability and its potential impact
  • Step-by-step reproduction steps including any affected URLs
  • Screenshots or proof-of-concept code, if available
  • Any tools or versions used during testing
  • Your name and contact information (for follow-up)
  • Whether you've discovered this vulnerability previously or reported it elsewhere
Important Safety Guidelines

Never: Access or modify user data that doesn't belong to you, perform testing that could disrupt our services for other users, or attempt to exploit a vulnerability beyond what's necessary to prove its existence.

What to Expect

After submitting your report, here's what you can expect from our security team:

Initial Response (24-48 hours)

We'll acknowledge receipt of your report and begin our initial assessment.

Validation & Triage (3-5 days)

Our team will reproduce and validate the vulnerability, assessing its severity.

Remediation Timeline

We'll share our timeline for fixing the issue, typically 30-90 days depending on complexity.

Public Disclosure

Once fixed, we'll coordinate public disclosure and publish an acknowledgment.

Contact Our Security Team

To report a security vulnerability, or if you have any questions about our disclosure program, please contact our security engineering team directly.

Security Vulnerabilities:
security@skoutai.io
Privacy & Data Protection:
privacy@skoutai.io
Legal Inquiries:
legal@skoutai.io
Customer Support:
support@skoutai.io

Our security team prefers encrypted communication when possible. If you would like to send sensitive information, please ask for our PGP key in your initial email.