Security researchers help keep SniffIt — and the millions of shoppers who rely on it — safe. If you've found a vulnerability, here's how to report it and what to expect in return.
SniffIt treats security reports as a first-class signal. When you report a vulnerability in good faith, we commit to:
The following assets are within scope for this program:
*.sniffit.app — marketing, dashboard, APIPlease don't test these — reports will be closed as out-of-scope.
Email [email protected]. For high-severity findings, please encrypt with the PGP key below.
A good report includes:
Subject: [SEC] Stored XSS in dashboard profile settings Asset: https://app.sniffit.app/settings/profile Impact: Executes arbitrary JS in victim's session Steps: 1. Log in and navigate to /settings/profile 2. Set display name to: <img src=x onerror=alert(1)> 3. Save, then view the profile as another user Expected: HTML escaping Actual: payload executes on render
We base severity on CVSS 3.1 plus real-world impact. Rewards scale with severity and quality of the report. Duplicates are paid for the first valid submission only.
We will not pursue civil or criminal action against researchers acting in good faith under this policy. Activity consistent with this policy is considered authorized, and we will work with you to understand and resolve the issue quickly.
If legal action is initiated by a third party against you for research conducted in compliance with this policy, we'll make it known that your activities were authorized.
With your permission, we publicly credit every researcher who reports a confirmed, in-scope vulnerability. If you'd rather stay anonymous, just say the word.
Recent credits: coming soon — be the first.
For encrypting sensitive reports:
A91F 4C0E 22B8 77D1 6E94 B3AA 58F2 0D1C 9E3F 42A6Questions about the program: [email protected]. Thank you for helping keep SniffIt safe.