Security Policy
Last updated: 8/31/2026
This Security Policy describes how security researchers may report vulnerabilities in DarkWebSonar services and sets expectations for responsible disclosure. It applies to darkwebsonar.io and the authenticated DarkWebSonar web application.
If you believe you have found a security issue, please report it to security@darkwebsonar.io before public disclosure.
1) How to report
Contact: security@darkwebsonar.io
Please include:
- A clear description of the vulnerability and affected component (URL, endpoint, or feature).
- Step-by-step reproduction instructions.
- Proof of concept or supporting evidence (screenshots, request/response samples, or minimal exploit code).
- Your assessment of impact (confidentiality, integrity, availability, or user harm).
- Whether you have tested only against accounts you own or control. We aim to acknowledge receipt within 2 business days. We will work with you in good faith to understand and remediate valid reports. Response and remediation timelines depend on severity and complexity.
2) In scope
The following are in scope for reports under this policy:
- darkwebsonar.io (marketing site, blog, and public pages).
- The DarkWebSonar web application (authentication, dashboard, monitoring, alerts, and related authenticated features).
- Netlify Functions and other first-party APIs operated by DarkWebSonar (e.g. contact, support, and subscription flows) when accessed through our domains.
- Application-level abuse and logic flaws in authentication and account flows, including missing anti-automation controls on password-reset or signup endpoints that enable targeted email flooding or other user harm.
3) Out of scope
The following are out of scope unless you can demonstrate a direct, exploitable impact on DarkWebSonar or our users:
- Third-party infrastructure and services we do not operate (e.g. Supabase, Netlify platform, Stripe, Polar, Resend, Cloudflare, Google OAuth, GitHub OAuth).
- Denial of service and volumetric or network-layer attacks (traffic floods, resource exhaustion, load testing). Note: application-level abuse of authentication flows — such as missing anti-automation on password-reset or signup endpoints that enables targeted email flooding or user harm — is in scope. The exclusion here covers raw volumetric DoS, not logic or anti-automation gaps.
- Spam, social engineering, or phishing targeting DarkWebSonar staff or users.
- Automated scanner output without a demonstrated, reproducible vulnerability.
- Best-practice or informational findings without exploitable impact (e.g. missing security headers, SSL/TLS configuration, cookie flags) unless tied to a concrete attack scenario.
- Physical security, insider threats, or issues requiring physical access to facilities.
- Vulnerabilities in third-party libraries or dependencies without a working exploit path in our deployment.
4) Rules of engagement
When testing under this policy:
- Use only test accounts you create and control. Do not access, modify, or exfiltrate data belonging to other users.
- Do not violate privacy laws or regulations.
- Do not degrade service availability (no DoS, load testing, or resource exhaustion). When demonstrating anti-automation or rate-limit gaps, use the minimum volume needed to prove the issue against an account you control, and stop once the behavior is shown.
- Do not send unsolicited email through our systems to third parties.
- Report findings privately to security@darkwebsonar.io and allow us reasonable time to investigate and remediate before any public disclosure.
- Do not exploit vulnerabilities beyond what is necessary to demonstrate impact. We reserve the right to suspend or block accounts or traffic that violate these rules or our Terms of Use.
5) Bug bounty
DarkWebSonar does not operate a paid bug bounty program. We appreciate good-faith security reports and may acknowledge researchers at our discretion. No compensation is offered unless explicitly agreed in writing.
6) Legal
Good-faith security research conducted in accordance with this policy is welcomed. Nothing in this policy grants permission to test outside the scope above or to act in ways that violate applicable law or our Terms of Use.
Section 5 of our Terms of Use prohibits unauthorized security testing, malware, and attempts to gain unauthorized access. Testing that does not follow this Security Policy is not authorized.
If you are unsure whether an activity is in scope, contact us at security@darkwebsonar.io before proceeding.
7) Safe harbor
We will not pursue legal action against researchers who:
- Act in good faith;
- Stay within this policy and the rules of engagement;
- Avoid privacy violations, data destruction, and service disruption; and
- Report issues promptly and allow reasonable remediation time. This safe harbor applies only to activities that comply with this policy and applicable law. It does not apply to access of other users' data, extortion, or public disclosure before we have had a reasonable opportunity to address the issue.
8) Questions
For security-related questions or to report an incident involving your account credentials, contact security@darkwebsonar.io.
For general support, use support@darkwebsonar.io. For legal or contractual matters, see legal@darkwebsonar.io in our Terms of Use.
To report a security issue, contact security@darkwebsonar.io