trust · security

Security

How we protect the data you trust us with, how our scanner behaves, and how to report a vulnerability.

Last updated 28 September 2026

How we protect data

Our scanner

Shorward's scanner is deliberately gentle. For each host it makes a few standard TLS handshakes on port 443 to see which protocol versions and key exchange groups the server accepts, and reads the public certificate. It doesn't try to log in, send exploits, crawl pages or fuzz inputs.

Report a vulnerability

If you find a security issue in shorward.com or the Shorward service, email [email protected] with the subject "Security report". We'll acknowledge it within 2 business days and keep you updated until it's fixed.

We won't take legal action against good-faith research that:

Out of scope: denial of service, social engineering, physical attacks, and reports from automated tools with no demonstrated impact. We don't run a paid bounty during the beta, but we're glad to credit you.

Machine-readable contact: /.well-known/security.txt