Disclosure policy
Anyone can point a public scan at any address, which means Lockvane sometimes learns something about an application belonging to someone who never asked us to look. This page says what we do about that, and how to tell us when Lockvane itself is the thing that is broken.
We do not publish results
A scan is shown to whoever ran it and to nobody else. There is no public directory of scanned sites, no leaderboard of insecure applications, and no feed. We do not sell findings, and we do not use them to market to the scanned party.
If your application was scanned by someone else, that scan sits in their account. It does not appear anywhere a stranger can browse.
Why a public scan is deliberately shallow
Anyone can type any address, so the free scan is limited to what your own visitors already receive: pages, delivered code, and response headers. It sends no payloads, writes nothing, and authenticates as nobody.
Everything that would tell you more, whether an unauthenticated request can read a particular table, whether a policy is enabled, whether a key in a repository is still live, is held behind proof that the asset belongs to the person asking. That gate is the disclosure policy doing its job, not a paywall. Paying us does not open it. Proving control does.
When a scan reveals something serious about a third party
Occasionally a passive scan surfaces something severe about an application the scanner does not own. In that case:
- We show the person who ran it what any visitor could already see, because that is all we read.
- We do not go further on that application. No deeper probing happens without ownership, even when the finding looks urgent.
- Where a finding is severe and we can identify a security contact for the affected party, we may notify them directly and privately. We will not name the person who ran the scan.
- We do not contact regulators, journalists, or the public.
If you are the owner of an application and want to know what a public scan of it reveals, run one yourself. It is free and takes about ninety seconds.
If you own an application someone else scanned
Write to security@lockvane.com from an address at that domain, or with any other evidence of control, and we will tell you whether the address was scanned and what a scan of it returns. We will not tell you who ran it.
You can also ask us to refuse future public scans of a hostname you control. We will honour that, and we will say plainly that it stops Lockvane looking, not anyone else.
Reporting a vulnerability in Lockvane
We would rather hear it from you than find out the hard way. Send it to security@lockvane.com with enough detail to reproduce it. We acknowledge within three working days and tell you what we intend to do.
A security product that could not take a bug report would be an embarrassing thing to sell, so this is a real address that a person reads.
Testing Lockvane: what is in bounds
We will not pursue you for good-faith research that follows these rules:
- Use only accounts and assets you own. Do not touch another customer’s data.
- Stop as soon as you have proof. Reading one record proves an access-control bug; downloading the table does not prove it harder.
- No denial of service, no load testing, no spam, and no social engineering of our people or providers.
- Do not publish before we have had a reasonable chance to fix it. Ninety days is our default, and we will usually be much faster.
- Do not use a finding to extract payment. We may thank you publicly if you want that, but we do not run a paid bounty.
Out of bounds: anything touching our providers’ own infrastructure, which is theirs to authorise, not ours.
What we do when we get one
- We confirm it and set a severity based on what an attacker could actually reach.
- We fix it, and if customer data was reachable we say so to the customers affected.
- We credit you by name if you want to be credited, and we leave you out entirely if you do not.
Questions about any of this: security@lockvane.com.