What you can test
- In scope: pages and first-party endpoints we control on databrokerremover.com and www.databrokerremover.com.
- Out of scope: brokers, and our email, hosting, DNS, payment and login providers — any vendor system.
- Only good-faith, non-destructive testing is allowed, and only as far as reporting a bug requires.
- Unsure? Ask before testing.
Rules for testing
- Never access, copy, change, keep or share another person’s data. If you hit some: stop, go no further, delete your copy when safe, and report the minimum.
- No social engineering, phishing, credential stuffing, password attacks, malware, denial of service, resource exhaustion, destructive tests, physical entry, or third-party testing.
- No spam, bulk accounts, real purchases, real broker requests, or anything that disturbs live data or uptime.
- Use the fewest requests and records that prove the bug, respect rate limits, and delete test data afterwards.
What to send us
- The URL, endpoint or component affected
- What it does, and the possible impact
- The fewest steps to reproduce it, without personal data or destructive proof
- Request or response details, with secrets removed
- The date and time you tested, plus a safe way to reach you
Email it to security@databrokerremover.com. We cannot receive encrypted email, so leave out passwords, payment details and government ID numbers.
What happens next
We aim to confirm a complete report within three business days, assess it within ten business days, and update you at least every 30 days until it is fixed. We may ask questions, or arrange a safe retest.
Please do not go public until the fix ships, or 90 days after your full report, whichever comes first — unless we agree another date, or active exploitation or immediate risk to people makes it urgent.
Safe harbor and rewards
Good-faith research that follows this policy is authorized. We will not start or recommend legal action over it alone. Hitting data by accident does not change that, as long as you stop, go no further, keep proof minimal, and report promptly.
If a third party acts, we can tell them your work followed this policy, but we cannot bind them. None of this covers deliberate breaches of the scope or the rules above. There is no bounty, no payment, and no promised credit.