Responsible Disclosure — DevMeth
Last updated: 2026-08-25
A security product should practice what it preaches. This page is how you report a vulnerability in DevMeth itself — the web app, the scan worker, or the live-probe infrastructure.
Scope
Our own product and scanning infrastructure. We do not act as a disclosure venue for vulnerabilities in third-party apps that happen to be scanned through the product — those should go to the app owner.
How to report
Email nick@devmeth.com. Include the affected surface, a reproducible description, and any evidence — but do not include full secrets you may have found while testing; describe rather than reproduce secret values.
What we commit
- Acknowledge valid reports within 5 business days.
- Aim to remediate critical issues within 90 days, and keep you informed.
- No legal action against good-faith researchers who avoid privacy violations and data destruction, access only what's needed to demonstrate the issue, and give us reasonable time to respond before any public disclosure.
No bounty
We do not currently run a bug-bounty program. We state this honestly rather than imply a reward. Your report is still genuinely appreciated.