Vulnerability Disclosure Policy
File: 19_Vulnerability_Disclosure_Policy.docx
SKRIB, INC.
Vulnerability Disclosure Policy
Last Updated: 26 May 2026
Skrib, Inc. (“Skrib”) treats the security of its users and their data as a first-order priority. We welcome reports of security vulnerabilities affecting Skrib’s products and infrastructure from anyone — security researchers, customers, users, and members of the public. This Vulnerability Disclosure Policy (this “Policy”) describes the assets that are in scope, how to report a vulnerability, what to expect from us, and the safe-harbour commitments that apply to good-faith research.
This Policy is not a bug-bounty programme; Skrib does not currently offer monetary rewards. Skrib will recognise contributors in writing on request, subject to verification.
1. In scope
The following Skrib-operated assets are in scope for this Policy:
https://skrib.com and any subdomain of skrib.com;
the production-tier APIs and web application served from those domains;
the Skrib client web application and any first-party browser extensions or desktop wrappers (where present); and
Skrib-controlled DNS, certificate, and email-authentication configurations (SPF, DKIM, DMARC, MTA-STS) for the skrib.com zone.
2. Out of scope
The following are out of scope for this Policy. Reports about these assets will not generally qualify for safe harbour and Skrib may decline to engage:
Third-party services that Skrib uses but does not operate (Stripe, Cloudflare, Clerk, AWS, OpenAI, Anthropic, Google). Please report directly to those vendors under their own security or VDP programmes.
Skrib’s marketing, careers, status, blog, and community sites where they are hosted on third-party platforms.
Social-engineering attacks against Skrib personnel or contractors, including phishing, vishing, and physical-access attacks.
Denial-of-service, traffic-flooding, brute-force credential-stuffing, or other availability-impacting techniques.
Findings from automated scans without a working proof-of-concept or impact analysis.
Missing best-practice headers (HSTS variants, CSP refinements) without a demonstrated security impact.
Self-XSS, clickjacking on pages without sensitive actions, missing rate limits without a demonstrated impact, and other low-severity findings without exploitability.
Findings affecting outdated browsers (more than two major versions out of date) or end-of-life operating systems.
Vulnerabilities in third-party libraries that have not yet been patched upstream and are not exploitable in the Skrib production context.
3. Reporting expectations
Please:
Report vulnerabilities by email to contact@skrib.com. PGP encryption is supported; the public key is at https://skrib.com/.well-known/security-key.asc.
Provide a clear, technical write-up of the vulnerability, including the affected URL or asset, the steps required to reproduce, the security impact, and any proof-of-concept code or screenshots.
Report each vulnerability separately. If you find a class of vulnerabilities, report a representative example and indicate where else it may apply.
Submit reports in English where possible. Skrib accepts reports in any language but response times may be longer for non-English reports.
4. Researcher conduct expectations
To qualify for safe harbour under this Policy, please:
Conduct testing only against assets you reasonably believe to be in scope and to belong to Skrib.
Make a reasonable effort to avoid privacy violations, the destruction or modification of data, and the disruption or degradation of Skrib services.
Do not access, modify, exfiltrate, or retain personal data of users (including your own colleagues’ data) beyond what is strictly necessary to demonstrate the vulnerability. Use test accounts you control wherever possible.
Do not attempt to exploit a vulnerability beyond what is necessary to demonstrate its existence and impact.
Do not engage in social-engineering, physical-access, or denial-of-service activities.
Provide Skrib with a reasonable opportunity to remediate before publicly disclosing the vulnerability, in line with Section 5.
If you inadvertently access, modify, or exfiltrate data that you should not have, stop testing, securely destroy any copies, and inform Skrib promptly.
5. Coordinated disclosure timeline
Acknowledgement of receipt: within five (5) business days.
Initial triage and severity assessment: within ten (10) business days of acknowledgement.
Status updates: at least every twenty (20) business days while the issue is open.
Target remediation: 30 days for critical-severity issues; 60 days for high-severity issues; 90 days for medium-severity issues; and 180 days for low-severity issues. Skrib may extend these targets in writing where remediation requires architectural changes or vendor coordination.
Public disclosure: at any time after the earlier of (i) Skrib confirming that the vulnerability has been remediated and (ii) Skrib and the researcher mutually agreeing in writing that public disclosure is appropriate. If Skrib has not been able to remediate within the target timeline above and has not provided a reasoned written extension, the researcher may make a reasonable, coordinated public disclosure after providing Skrib with at least fifteen (15) further calendar days’ notice.
6. Safe harbour
Skrib will treat security research conducted in good faith and in accordance with this Policy as authorised under the Skrib Terms of Service and the Acceptable Use Policy. To the extent any of the activities described in this Policy could otherwise constitute unauthorised access, contractual breach, or copyright infringement under applicable law (including the United States Computer Fraud and Abuse Act, 18 U.S.C. § 1030; the Digital Millennium Copyright Act anti-circumvention provisions, 17 U.S.C. § 1201; the UK Computer Misuse Act 1990; and analogous laws), Skrib waives any related claim against the researcher to the maximum extent permitted by law, provided that the researcher has acted consistently with this Policy and in good faith.
Skrib will not pursue or support legal action against a researcher who acts in good faith and consistently with this Policy. If a third party brings a claim against a researcher in connection with research conducted under this Policy, Skrib will, on request, take reasonable steps to make clear to the third party that the research was authorised.
This safe harbour does not authorise testing on third-party systems or on systems Skrib does not control, and does not waive any rights of third parties (including users of the Skrib platform). It also does not authorise activities that violate applicable law in the researcher’s jurisdiction or in the jurisdiction of the affected systems.
7. Confidentiality
Skrib treats vulnerability reports as confidential where reasonably possible. Skrib may share the substance of a report with affected third parties (such as upstream vendors), with Skrib’s personnel and advisers, and with regulators where required. Skrib will not share the researcher’s identity with third parties without the researcher’s consent, except where required by law.
8. Recognition
Skrib maintains a Hall of Thanks at https://skrib.com/security/hall-of-thanks recognising researchers who have made a meaningful security contribution. Recognition is opt-in; please indicate in your report whether you would like to be listed and the name and (optional) URL to be used.
9. Contact
Email: contact@skrib.com
PGP key: https://skrib.com/.well-known/security-key.asc
Security.txt: https://skrib.com/.well-known/security.txt
General legal contact: contact@skrib.com
10. Updates
Skrib may update this Policy from time to time. The current version, and the date on which it was last updated, are indicated in the metadata header at the top of this document.