Binding Legal Safe Harbor · Coordinated Vulnerability Disclosure

Vulnerability Disclosure Policy

At PrivacyScrubber, security is rooted in verifiable client-side isolation. We value the vital contributions of independent cybersecurity researchers and are committed to clear, collaborative, and safe vulnerability remediation.

< 24h
Triage SLA

Initial assessment response

Safe Harbor
Legal Protection

No legal action for good faith research

4 Surfaces
Research Scope

Web, Ext, MCP Server & SDK

Hall of Fame
Public Recognition

Security advisories & credits

1. Legal Safe Harbor Commitment

Formal legal authorization for ethical security researchers.

If you conduct security research in good faith and in compliance with this policy, PrivacyScrubber agrees to the following protections:

  • No Legal Action: We will not pursue civil claims or initiate criminal complaints under the Computer Fraud and Abuse Act (CFAA), DMCA § 1201, or equivalent international cyber laws.
  • Explicit Authorization: We consider your activities to be authorized access under applicable anti-hacking statutes.
  • Third-Party Support: If a third party initiates legal action against you for activities conducted strictly within the scope of this policy, we will provide formal confirmation that your research was authorized by us.

2. Program Scope Matrix

Specific targets and vulnerability classifications.

In-Scope Targets & Vulnerabilities
  • Client-Side Data Exfiltration: Any vector that bypasses the zero-network policy or transmits unencrypted text to an external server during active scrubbing.
  • DOM XSS & SessionMap Extraction: Cross-site scripting vulnerabilities capable of extracting in-memory token dictionaries.
  • Cryptographic Faults: Flaws in TEAMS Argon2id key derivation, XChaCha20-Poly1305 session vaults, or CSPRNG entropy generation.
  • MCP Server & SDK Privilege Escalation: Local IPC socket leaks or memory corruption in @privacyscrubber/mcp-server or @privacyscrubber/sdk.
  • Regex Denial of Service (ReDoS): Pathological input patterns causing unbounded thread hangs or CPU locking in Web Workers.
Out-of-Scope Activities
  • NER / Regex Statistical Misses: Typographical omissions or missed names are accuracy tuning items, not security flaws (submit via GitHub issues).
  • Denial of Service (DoS/DDoS): Volumetric traffic flooding directed at static hosting (Vercel/Cloudflare CDN).
  • Third-Party Gateway Flaws: Issues strictly inside Paddle.com or PayPal hosted checkout frames.
  • Social Engineering: Phishing or physical attacks against employees or contractors.

3. Reporting Protocol & Remediation SLAs

How to submit encrypted vulnerability reports.

Please send all vulnerability reports directly to our security engineering desk at security@privacyscrubber.com.

For sensitive proof-of-concept exploits, please encrypt your email using our PGP public key:

PGP Fingerprint:8B2E 94F1 A7C3 519D 00E4 782B C619 4480 E35A 91BC
Email: security@privacyscrubber.com
Key ID: 0xE35A91BC
< 24 Hours
Initial Triage SLA
< 72 Hours
Validation & Severity Score
< 14 Days
Patch Release & Advisory