Responsible Disclosure
Effective 14 July 2026
Scout is a security product, so we hold ourselves to the standard we hold others to. If you find a vulnerability in Scout itself, please tell us — we'll respond, fix it, and credit you.
How to report
Email security@dimsylaisolutions.com with enough detail to reproduce the issue: what you found, where, the impact, and clear steps. A proof-of-concept helps. See our machine-readable contact at /.well-known/security.txt.
Our commitment
- We aim to acknowledge your report within a few business days.
- We'll investigate, keep you updated, and let you know when it's fixed.
- We're happy to credit you publicly for a valid report (or keep you anonymous — your choice).
- We will not pursue legal action for good-faith research that follows this policy.
Ground rules for good-faith research
- Only test your own Scout account and data — do not access, modify, or delete other users' accounts, scans, or data.
- Don't run denial-of-service, spam, or brute-force attacks, or otherwise degrade the service for others.
- Don't use social engineering, phishing, or physical attacks against Scout, its staff, or its infrastructure providers.
- Give us reasonable time to fix an issue before disclosing it publicly, and don't exfiltrate or publish any data you happen to access.
Scope
In scope: scoutmy.app and api.scoutmy.app. Out of scope: our third-party providers (Stripe, Anthropic, Netlify, Hetzner, Cloudflare, GitHub, Google) — report issues in those to the respective vendor. This is a good-faith program, not a paid bug-bounty; we may offer recognition and, at our discretion, a token of thanks.
Contact
DIMSYL AI SOLUTIONS LLC — security@dimsylaisolutions.com.