Vulnerability Disclosure Policy

Last updated: 2026-07-20

Scope

This policy applies to the dumpthis.sh web application, its API (/api/*), the SYNACK protocol (/.well-known/synack), and all subdomains served from this origin.

Third-party services linked from this site are out of scope. Please report issues with those services to their respective operators.

How to Report

Send vulnerability reports to v@dumpthis.sh. Include:

Safe Harbor

When researching vulnerabilities under this policy, we consider your activities to be:

This safe harbor applies only to activities conducted in good faith and in accordance with this policy. If a third party asserts a legal claim against you for activities conducted under this policy, we will make it clear that your actions were authorized.

Ground Rules

Response Timeline

We aim to:

This is a one-person operation. Response times may vary, but every report is read and taken seriously.

Recognition

We are happy to credit researchers by name or handle in release notes and on this page, with your permission. We do not offer monetary bounties at this time.

← security.txt