generated: '2026-08-26' method: searched source: https://www.scriptainsights.com/security program: present: true type: responsible-disclosure-policy name: Responsible Vulnerability Disclosure Policy url: https://www.scriptainsights.com/security status: 200 bug_bounty: false bounty_platform: null paid: false safe_harbor: partial safe_harbor_note: >- Reports "submitted in good faith and pursuant to this Policy will be handled appropriately and kept confidential where permitted by law." The policy does NOT contain an explicit legal safe-harbor / no-legal-action clause, and it explicitly reserves that "there is no guaranteed response or action for any specific type or class of issue reported." contact: email: security@scriptainsights.com note: >- Reporting address, stated as intended only for vulnerability reports and not for technical support. Encryption of sensitive report contents is requested but no PGP key is published. pgp_key: null scope: in_scope: Any public-facing system owned, operated, or controlled by Scripta Insights. out_of_scope: - Disruptive testing — load/performance testing, denial of service, or anything interfering with confidentiality, integrity, availability or operation - Social engineering or phishing of employees or associated individuals - Altering content on websites, applications, or social media accounts - Retaining any customer data accessed during testing - Posting, transmitting, uploading, linking to, sending or storing malicious software - Testing that transmits unsolicited, junk, spam, or unauthorized e-mail - Testing third-party applications, websites or services that integrate with or link to Scripta services - Physical office access testing (doors, tailgates, windows, metal detectors) - Attempted or actual alteration of account privileges or login credentials - Extortion data_handling_requirement: >- Researchers must limit accessed data to the minimum required to demonstrate a proof of concept and must cease testing and report immediately if PII, PHI, credit card data or proprietary information is encountered. coordinated_disclosure: embargo: >- Researchers must not disclose publicly or to any third party until Scripta has had a reasonable opportunity to assess, validate and resolve, and has communicated in writing that disclosure may proceed. sla: null sla_note: Response is "as soon as possible"; no numeric SLA is committed. machine_readable: security_txt: false security_txt_probe: url: https://www.scriptainsights.com/.well-known/security.txt status: 400 gap: >- The policy and contact exist only as prose on an HTML page. Publishing RFC 9116 /.well-known/security.txt with Contact, Policy, Preferred-Languages and Expires would make this machine-discoverable at essentially zero cost. evidence: - url: https://www.scriptainsights.com/security status: 200 - url: https://www.scriptainsights.com/.well-known/security.txt status: 400