DugganUSA Vulnerability Disclosure Policy and Researcher Hall of Fame
If you have found a security problem in something DugganUSA runs, thank you. This page tells you how to report it, what we will do, and what we promise not to do.
How to report
Email [email protected]. Tell us the affected host or URL, the steps to reproduce, what you were able to see or change, and when you tested. Screenshots and request and response pairs help. You do not need to confirm the channel first; send the report.
Our machine-readable contact file is at https://analytics.dugganusa.com/.well-known/security.txt.
What is in scope
Systems we operate: analytics.dugganusa.com and its APIs, the STIX and CSV threat feeds, our MCP servers, security.dugganusa.com, finops.dugganusa.com, aipmsec.com, epstein.dugganusa.com and the infrastructure behind them.
Our blog at www.dugganusa.com is hosted by Wix. Report problems in Wix itself to Wix. Report anything we configured on top of it, such as embedded code or redirects, to us.
What is out of scope
Denial of service, load testing or anything that degrades the service for other users. Social engineering, phishing or physical attacks against us or anyone else. Spam or automated submissions through our forms. Findings that only restate public threat data we publish on purpose, such as indicators in our feed. Third-party services we use but do not run.
Rules of engagement
Test only against your own account or data. Stop and tell us as soon as you reach data that is not yours, and do not keep, copy or share it. Do not modify or delete anything. Give us a reasonable time to fix the problem before you publish, and we will agree a date with you.
What we will do
We are a two-person company, so we will be straight about timing. We will confirm we received your report within two business days, tell you whether we could reproduce it, and keep you updated until it is fixed. If you follow this policy, we will not take legal action against you or ask anyone else to, and we will say so in writing if you need it.
We do not pay cash bounties. We will credit you by name, or by handle if you prefer, on the hall of fame below once the fix is live, and we will write up the finding on our blog if you want us to.
Researcher hall of fame
No researcher has been credited here yet. The first confirmed report goes at the top of this list.
Was this useful? Rate this post. The widget is at the bottom of the page, and we read every response.
Every indicator in this post is in the feed. Free.
1.58M+ IOCs, STIX 2.1 / TAXII, 88% novel vs ThreatFox, exploited-CVE leads ahead of CISA. No credit card — a free API key in 30 seconds, and you can audit every claim above against the live endpoints.
Was this useful? Thirty seconds, no cookies, no tracking, no third parties, your address hashed and never stored. If the box below does not load, the same question lives at https://analytics.dugganusa.com/nps.html?post=dugganusa-vulnerability-disclosure-policy-and-hall-of-fame



Comments