Responsible Disclosure Policy
How to securely report security vulnerabilities to Scalewidth.
Last Updated: May 27, 2026
Our Commitment
Scalewidth takes the security of our systems seriously. We value the contributions of the security research community and encourage responsible disclosure of vulnerabilities. We commit to acknowledging, investigating, and remediating reported security issues in a timely manner.
Scope
This policy applies to all Scalewidth websites, APIs, cloud infrastructure, SaaS platforms, and related systems. Out of scope issues include: rate limiting, missing HTTP headers, self-XSS, social engineering, physical attacks, and third-party services.
How to Report
Submit vulnerability reports to: security@scalewidth.com
Include in your report: affected URL/component, vulnerability type, steps to reproduce, proof of concept, impact assessment, and your contact information. PGP-encrypted reports are preferred. Request our PGP key by email.
Guidelines
- Do not access or modify data beyond what is necessary to demonstrate the vulnerability
- Do not perform denial-of-service, social engineering, or physical attacks
- Delete any data accessed during testing after reporting
- Allow reasonable time for remediation before public disclosure
- Act in good faith to avoid harm to Scalewidth and its users
Response Commitment
- Acknowledgment: Within 24 hours for critical, 72 hours for standard
- Verification: 5 business days
- Remediation: 30-90 days depending on severity
- Recognition: We maintain a security researcher hall of honor