Vulnerability Disclosure Policy
At PrivacyScrubber, security is rooted in verifiable client-side isolation. We value the vital contributions of independent cybersecurity researchers and are committed to clear, collaborative, and safe vulnerability remediation.
Initial assessment response
No legal action for good faith research
Web, Ext, MCP Server & SDK
Security advisories & credits
1. Legal Safe Harbor Commitment
Formal legal authorization for ethical security researchers.
If you conduct security research in good faith and in compliance with this policy, PrivacyScrubber agrees to the following protections:
- No Legal Action: We will not pursue civil claims or initiate criminal complaints under the Computer Fraud and Abuse Act (CFAA), DMCA § 1201, or equivalent international cyber laws.
- Explicit Authorization: We consider your activities to be authorized access under applicable anti-hacking statutes.
- Third-Party Support: If a third party initiates legal action against you for activities conducted strictly within the scope of this policy, we will provide formal confirmation that your research was authorized by us.
2. Program Scope Matrix
Specific targets and vulnerability classifications.
- Client-Side Data Exfiltration: Any vector that bypasses the zero-network policy or transmits unencrypted text to an external server during active scrubbing.
- DOM XSS & SessionMap Extraction: Cross-site scripting vulnerabilities capable of extracting in-memory token dictionaries.
- Cryptographic Faults: Flaws in TEAMS Argon2id key derivation, XChaCha20-Poly1305 session vaults, or CSPRNG entropy generation.
- MCP Server & SDK Privilege Escalation: Local IPC socket leaks or memory corruption in
@privacyscrubber/mcp-serveror@privacyscrubber/sdk. - Regex Denial of Service (ReDoS): Pathological input patterns causing unbounded thread hangs or CPU locking in Web Workers.
- NER / Regex Statistical Misses: Typographical omissions or missed names are accuracy tuning items, not security flaws (submit via GitHub issues).
- Denial of Service (DoS/DDoS): Volumetric traffic flooding directed at static hosting (Vercel/Cloudflare CDN).
- Third-Party Gateway Flaws: Issues strictly inside Paddle.com or PayPal hosted checkout frames.
- Social Engineering: Phishing or physical attacks against employees or contractors.
3. Reporting Protocol & Remediation SLAs
How to submit encrypted vulnerability reports.
Please send all vulnerability reports directly to our security engineering desk at security@privacyscrubber.com.
For sensitive proof-of-concept exploits, please encrypt your email using our PGP public key:
