Vulnerability Disclosure Policy
Last updated: 2026-07-20
Scope
This policy applies to the dumpthis.sh web application, its API (/api/*), the SYNACK protocol (/.well-known/synack), and all subdomains served from this origin.
Third-party services linked from this site are out of scope. Please report issues with those services to their respective operators.
How to Report
Send vulnerability reports to v@dumpthis.sh. Include:
- A clear description of the vulnerability and its impact
- Steps to reproduce (as specific as possible)
- Any proof-of-concept code or screenshots
- Your preferred method of credit (name, handle, or anonymous)
Safe Harbor
When researching vulnerabilities under this policy, we consider your activities to be:
- Authorized under applicable anti-hacking laws
- Exempt from DMCA circumvention claims for the limited purpose of testing
- Protected from civil claims by the operator of dumpthis.sh
This safe harbor applies only to activities conducted in good faith and in accordance with this policy. If a third party asserts a legal claim against you for activities conducted under this policy, we will make it clear that your actions were authorized.
Ground Rules
- Do not exfiltrate, modify, or delete data beyond what is necessary to demonstrate the vulnerability
- Do not disrupt production services or degrade the experience of other users
- Do not publicly disclose the vulnerability before we have had a reasonable opportunity to address it
- Do not engage in social engineering, phishing, or physical attacks against users or infrastructure
Response Timeline
We aim to:
- Acknowledge your report within 5 business days
- Provide an initial assessment (accepted / needs more info / out of scope) within 10 business days
- Resolve or mitigate validated issues within 90 days, with status updates along the way
This is a one-person operation. Response times may vary, but every report is read and taken seriously.
Recognition
We are happy to credit researchers by name or handle in release notes and on this page, with your permission. We do not offer monetary bounties at this time.