Skip to content

Security: TokenScanAI/tokenapi-scan

Security

SECURITY.md

Security Policy

Reporting a vulnerability

If you discover a security issue in this repository, the hosted service at tokenscanai.com, or in any artifact published by the TokenScanAI organization, please report it privately so we can address it before public disclosure.

Preferred channel

GitHub Security Advisory (private): https://github.com/TokenScanAI/tokenapi-scan/security/advisories/new

What we want

A clear, minimal report containing:

  • What is vulnerable — the URL, endpoint, parameter, or artifact.
  • Reproduction — steps a third party can follow to reproduce the issue.
  • Impact — what an attacker can do (data exposure, integrity, availability).
  • (Optional) Proposed fix — if you have one.

Out of scope

  • Issues already documented in public reports or known-issues lists.
  • Issues that require a previously compromised browser, OS, or network.
  • Vulnerabilities in third-party services we depend on — please report those directly to the upstream maintainer.
  • Spam, phishing, or third parties impersonating the service.

Disclosure timeline

  • 24 h — acknowledgement.
  • 7 d — triage and severity classification.
  • 30–90 d — fix + coordinated disclosure (CVE if applicable).

What we will NOT do

  • Threaten legal action for good-faith research conducted under this policy.
  • Publish reporter identities without explicit consent.

Detection-result disputes

Disagreements with a detection result on tokenscanai.com are not security issues. Open a GitHub Discussion or contact via the live site. Every detection ships with replayable evidence; if the evidence is wrong, it can be re-tested.


Thanks for keeping TokenAPI Scan honest.

There aren't any published security advisories