Security at ScripticX
How we approach platform safety and vulnerability reports.
If you believe you found a security vulnerability, report it privately using our contact form. Please do not publish details before we have had a reasonable opportunity to investigate.
Our approach
ScripticX treats security as an ongoing engineering responsibility. We aim to reduce risk through careful access control, dependency maintenance, secure defaults, and clear handling of vulnerability reports.
We do not claim certifications that have not been independently completed and verified. When our security posture changes, this page will be updated with specific and supportable information.
Responsible disclosure
Send reports using our contact form and include:
- a clear description of the issue;
- the affected page, feature, or endpoint;
- steps that reproduce the behavior;
- the likely impact;
- supporting screenshots or a minimal proof of concept.
Please use test accounts and avoid accessing, changing, or deleting another person's information.
What to report
Useful reports may include authentication bypasses, unauthorized access to private information, injection vulnerabilities, privilege escalation, or security issues in the code execution environment.
Reports about missing security headers, automated scanner output without demonstrated impact, or social engineering generally receive lower priority.
What to expect
We aim to acknowledge a complete report within five business days. Investigation and remediation timelines depend on severity and complexity.
Submitting a report does not guarantee a reward. If a formal security reward program is introduced, its eligibility rules will be published here.