SKOPAQ AI PRIVATE LIMITED takes security reports seriously, for its products, its public repositories and its website alike. Thank you for taking the time to tell us about a problem rather than exploiting it.
Do not open a public issue, discussion or pull request for a security problem. A public report tells attackers before it tells us.
Report privately, by either route:
- Email — preferred. solutions@skopaq.com, with
[SECURITY]at the start of the subject line. - GitHub private vulnerability reporting. The repository's Security tab → Report a vulnerability, where it is enabled.
Please give us a reasonable window to fix the problem before publishing.
If you found a credential or key that appears to belong to SKOPAQ AI — in a repository, its git history, a built artefact or a deployed bundle — treat it as urgent and say so in the subject line.
The more of this we get, the faster the fix:
- The repository, URL or product, and which part of it.
- Environment: browser and version, operating system, runtime, and viewport if it is layout-dependent.
- Step-by-step reproduction, starting from a clean state.
- A proof of concept — a request, a payload, a short recording.
- The impact you believe it has, and any prerequisites (a specific browser, an authenticated third-party service, a particular configuration).
- Whether you have shared this with anyone else, and any disclosure deadline you intend to hold us to.
We acknowledge every report. If we conclude a report is not a vulnerability, we explain why rather than close it silently. We tell you when the fix is live, and we are glad to credit you by name or handle if you would like that.
We do not currently run a paid bug bounty. Reports are still welcome, and credit is offered gladly.
Fixes land on the default branch of the repository concerned, and the website is
continuously deployed from its main branch. Older commits, tags, forks and mirrors are
not supported — update to the current default branch.
In scope
- The website as deployed at
skopaq.comand atskopaq.ai. Both hostnames serve the same application;skopaq.comis the canonical one. - The public repositories in this organisation, and anything their built artefacts expose — leaked secrets, injectable markup, unsafe handling of input, dependency vulnerabilities with a demonstrated path to exploitation.
- Supply-chain issues in a committed dependency tree.
- Anything else SKOPAQ AI operates.
Out of scope
- Findings from an automated scanner with no working proof of concept, and "outdated dependency" reports with no exploitable path in the code concerned.
- Missing security headers, TLS configuration, or DNS/CDN settings on infrastructure we do not control — report those to the relevant provider, though we are happy to hear about them.
- Volumetric denial of service, load testing, and spamming the contact form.
- Self-XSS, and issues requiring a physically compromised device, a malicious browser extension, or an already root-compromised OS.
- Clickjacking or missing anti-CSRF on pages with no authentication and no state-changing action.
- Social engineering of SKOPAQ AI staff or clients.
- Vulnerabilities in the upstream of a repository we have forked. Report those to the upstream project; report anything specific to our fork to us.
- The separate Skopaq: Your AI QA Engineering Team product, which is not built from
any repository here and is no longer served at
skopaq.ai. Reports about it are welcome at the same address, but they are not in scope for this policy.
We will not pursue or support legal action against anyone who, in good faith:
- reports promptly and privately through the channels above,
- limits testing to what is necessary to demonstrate the issue,
- does not access, modify, exfiltrate or destroy data belonging to SKOPAQ AI, its clients or its users,
- does not degrade the service for others, and
- gives us reasonable time to fix the issue before disclosing it publicly.