Skip to content
Scaan Technologies
· DraftPlaceholder pending counsel review
Security · Disclosure

Responsible Disclosure.

Last updated · 2026-05-13

Scaan Technologies welcomes reports of security issues from researchers and operators acting in good faith. This policy sets out how to report a vulnerability in this site or in publicly accessible Scaan infrastructure, and what you can expect from us in return.

Customer-deployed Scaan platforms operate on customer infrastructure under separate engagement agreements; vulnerabilities found in those deployments should be reported through the agreement's designated channel, not through this policy.

  1. 01

    Scope

    This policy applies to:

    • scaan.tech and its subdomains
    • Publicly accessible Scaan corporate infrastructure
    • Source code and binaries that Scaan distributes publicly (if any)

    The following are out of scope:

    • Customer-deployed Scaan platforms running on customer infrastructure
    • Third-party services that we depend on
    • Social engineering of Scaan personnel or partners
    • Denial-of-service activity of any kind, including resource exhaustion
  2. 02

    How to Report

    Send vulnerability reports to security@scaan.ai. Where possible, encrypt the contents using the published PGP key.

    [PGP fingerprint to be added — security team to provision.]

    A good report includes:

    • A clear description of the issue and its impact
    • Reproduction steps
    • The URL, endpoint, or component affected
    • Any proof-of-concept artifacts
    • Your preferred public credit (or anonymity)
  3. 03

    Safe Harbour

    Scaan will not pursue civil action or initiate complaints to law enforcement for security research conducted in good faith and in accordance with this policy. Good faith means:

    • Stopping at proof-of-impact — no data exfiltration beyond what is needed
    • Avoiding privacy violations and destruction or modification of data
    • Reporting the issue promptly
    • Giving us reasonable time to fix the issue before disclosure
  4. 04

    What to Expect

    When we receive a report we will:

    • Acknowledge receipt within two business days
    • Investigate, validate the finding, and keep you informed of progress
    • Coordinate disclosure once the issue is fixed, with credit to you if you wish

    Scaan does not currently operate a paid bug bounty programme. We may offer public acknowledgement and, where appropriate, a token of thanks.

  5. 05

    Contact

    Reports: security@scaan.ai. Please use the PGP key published alongside this policy for anything sensitive.