Security & Vulnerability Disclosure
Last updated: 2026-08-07
These are product starter templates for SlaySlop. Have qualified counsel review them before relying on them in production. Governing law and registered entity details remain TBD.
Our commitment
We take the security of SlaySlop and our customers seriously. We welcome good-faith reports from independent researchers and customers.
Machine-readable contact details are published at /.well-known/security.txt.
How to report
Email security@slayslop.com with a clear description of the issue, affected URLs or components, steps to reproduce, and any proof-of-concept that demonstrates impact without causing harm.
Please include a contact method so we can follow up. Encrypted email may be offered later; until then, avoid sending unnecessary sensitive customer data.
Safe harbor
If you make a good-faith effort to follow this policy, avoid privacy violations, service disruption, and data destruction, and do not exploit an issue beyond what is needed to demonstrate it, we will not pursue legal action related to that research.
This safe harbor does not authorize testing of customer sites through SlaySlop without the site owner's permission, nor testing that violates applicable law.
What is in scope
- Authentication and session issues on slayslop.com and the SlaySlop API.
- Cross-tenant data exposure or broken access control in the product.
- Injection, SSRF, or remote code execution in SlaySlop-controlled systems.
- Significant misconfigurations that expose secrets or customer data.
What is out of scope
- Social engineering, phishing, or physical attacks.
- Denial-of-service or volumetric testing against production.
- Reports from automated scanners with no demonstrated impact.
- Issues in third-party services outside our control, unless they expose SlaySlop customer data due to our misconfiguration.
- Unauthorized scanning of websites that are not yours via our product (see Acceptable Use).
Our process
We aim to acknowledge reports within 5 business days and to provide a status update within 30 days where feasible. Complex issues may take longer.
Please give us a reasonable window to investigate and remediate before any public disclosure. Coordinated disclosure timelines can be discussed after we confirm the issue.
Recognition
We may thank researchers who submit valid, in-scope reports. We do not currently operate a paid bug bounty; terms may change and will be announced here if they do.
Contact
Security: security@slayslop.com. General support: support@slayslop.com.
Related policies