Vulnerability Disclosure Process

Vulnerability Disclosure Process
Scan2x takes the security of its products, services, and customers seriously. We welcome reports from security researchers and members of the public who believe they have identified a potential security vulnerability.
- The affected product, service, website, or version
- A description of the vulnerability
- Steps required to reproduce the issue
- The potential security impact
- Any supporting screenshots, logs, or proof-of-concept code
- Your preferred contact details
- Acknowledge receipt within three business days
- Review and validate the reported issue
- Keep you informed of material progress
- Work with you to understand and resolve the vulnerability
- Coordinate public disclosure where appropriate
- Avoid accessing, modifying, downloading, or deleting data belonging to others
- Avoid disrupting our services or affecting system availability
- Do not use social engineering, phishing, physical attacks, or denial-of-service testing
- Do not introduce malware or use automated tools that generate excessive traffic
- Stop testing and notify us immediately if you encounter personal, confidential, or customer information
- Give us a reasonable opportunity to investigate and address the issue before making it public