Status: draft, published for review. The hosted service has been live in beta at https://perimeterwatch.org since 30 September 2026. It has had no independent security review, and no lawyer has reviewed this policy. The legal documents are drafts under review and are not yet in force. The reporting address below works today. For a vulnerability in the open-source software, see SECURITY.md as well.
Last updated: 30 September 2026
This policy is for people who find a security problem in the service itself. If you operate a host that received traffic from the service and you want it to stop, see the opt-out policy.
"README open question" followed by a number refers to the list of open questions in the repository.
1. Scope
In scope
| Target | Detail |
|---|---|
| The hosted service | https://perimeterwatch.org. No other host name is in scope. |
| The open-source software | The perimeterwatch command-line tool and the scanning engine, in the project's public repository at https://github.com/erik1o6/perimeterwatch |
Reports we especially want
- A way for one customer to see another customer's data.
- A way to obtain findings about individual people for a domain that is not verified.
- A way to pass domain verification without controlling the domain's DNS.
- A way to make the service contact a host outside the verified domain, or a private or reserved address.
- A way to make the service send anything other than a plain GET or HEAD request during exposure checks.
- A way to make the service run active checks without authorisation.
- A way to read stored findings, staff addresses or tokens without the encryption key.
- A way to recover a found credential from what the service stores about it.
- A way to change or delete audit log entries.
- A way to sign in as someone else, or to use a sign-in link or session that is not yours.
- A way to open a finding about a person, or download a report with personal details shown, without an audit log entry being written.
- A way to make the service contact a host or address on its do-not-contact list.
- A way to make the alert function send requests to an address other than Slack, Discord or Telegram.
- A way to read a stored webhook address or bot token through the service's pages.
- A way to run commands on the service through a crafted host name, DNS answer, repository or tool output.
Out of scope
- Systems of our customers. A finding about a customer's system is the customer's to receive, not yours to test.
- Systems of our providers and data sources, such as Hetzner, Cloudflare, Resend, GitHub, Have I Been Pwned or crt.sh. Report to them.
- Reports from automated scanners with no demonstrated effect.
- Missing security headers or cookie flags with no demonstrated effect.
- Denial of service by volume.
- Social engineering of the operator, its contractors or customers.
- Physical attacks.
- Email spoofing reports that do not show an actual weakness in our published records.
2. Safe harbour
These promises are made by the operator. Today that is the maintainer, who runs the service as an individual while a non-profit entity is being set up.
If you act in good faith and follow this policy:
- We will treat your research as authorised by us.
- We will not bring legal action against you, and we will not ask the police or a prosecutor to act against you, for that research.
- We will not treat your research as a breach of our terms of service.
- If someone else brings legal action against you for research that followed this policy, we will say publicly that you acted with our authorisation.
Limits of this promise:
- We can only authorise testing of our own systems. We cannot authorise testing of systems owned by customers, providers or anyone else.
- We cannot bind a prosecutor or a court.
- If you are unsure whether something is covered, ask us first at the address below.
For legal review confirm that the entity may give these promises, and adapt them to the chosen jurisdiction. See README open question 27.
3. What we ask of you
Do:
- Use only accounts and domains that are your own.
- Respect the limits of the sign-in form. Do not request sign-in links for addresses that are not yours.
- Stop as soon as you have shown that the problem exists.
- Report promptly.
- Give us reasonable time to fix the problem before you publish.
Do not:
- Read, copy, change or delete data that is not yours. If you come across such data, stop, do not keep it, and tell us what you saw.
- Use a weakness to reach further into our systems than is needed to show it exists.
- Degrade the service for others.
- Use the service to scan a domain you are not authorised to have scanned, even as a test.
- Test with real personal data of other people.
- Send unsolicited messages to our customers or to the operator's contractors.
- Demand payment as a condition of reporting.
4. How to report
| Address | security@perimeterwatch.org |
| Encryption | None. No PGP key exists. Reports go by plain email. If your report holds something that must not travel in plain email, say so in a first message and we will agree another way. |
| Languages | English |
| Machine-readable copy | https://perimeterwatch.org/.well-known/security.txt |
Private vulnerability reporting on GitHub is not switched on for the repository. Please use the email address above, and do not open a public issue for a security problem.
Please include:
- What the problem is and where.
- Steps to reproduce it.
- What an attacker could do with it.
- The version of the software, or the date and time of your test.
- Whether you want to be named when the fix is announced.
Please do not include personal data of other people or live credentials. Tell us that they exist and where.
5. What you can expect from us
| Step | Target |
|---|---|
| Acknowledge your report | 3 working days |
| First assessment, with our view of severity | 10 working days |
| Progress updates | Every 14 days until closed |
| Fix for a problem that exposes customer or personal data | 30 days |
| Fix for other problems | 90 days |
These are targets, not guarantees. The service is run by one person.
6. Publication
- We ask you not to publish before a fix is released, or before 90 days after your report, whichever comes first.
- If we need longer, we will ask you and explain why.
- When a fix is released we publish a notice that describes the problem.
- We name you in the notice if you wish.
7. Rewards
We do not pay rewards. The service is free.
8. If personal data was exposed
If your report shows that personal data was or could have been exposed, we assess whether we must notify customers and authorities. We may ask you for more detail to do that.
9. Your personal data
We use your name and contact details to handle your report and, if you wish, to name you. We keep your report and our replies for 12 months after the matter is closed. See the privacy policy.