Skip to content
Security

Security & disclosure

We built a tool to stop security shakedowns, so it would be a bad look to be an easy mark ourselves. Here's how we lock the swamp down — and how to tell us if we missed something.

Last updated: July 8, 2026

How we secure buckingfugs

  • Nothing to steal.There are no user accounts, no passwords, and no personal profiles. We don't log IPs or user-agents.
  • Hardened headers. Strict Content-Security-Policy, HSTS with preload, X-Content-Type-Options: nosniff, X-Frame-Options: DENY, and a locked-down Permissions-Policy — the same hygiene the scanner checks for.
  • Passive scanning only. The scanner reads public DNS and public HTTP responses. It never attacks, exploits, or alters a target.
  • Payments offloaded. Tips are processed by Stripe; we never handle or store raw card data.

Reporting a vulnerability

Found a security issue in the Service? Please tell us. Email hello@buckingfugs.com, or see our /.well-known/security.txt. Helpful reports include:

  • A clear description of the issue and where it is.
  • Steps to reproduce, or a proof of concept.
  • The impact you think it has.

Our commitment (safe harbor)

If you make a good-faith effort to follow this policy, we will not pursue legal action against you for your research, and we'll work with you to understand and fix the issue promptly. We aim to acknowledge reports quickly and keep you in the loop as we remediate.

Please don't

  • Access, modify, or delete data that isn't yours.
  • Run denial-of-service tests, spam, or social-engineering attacks.
  • Publicly disclose an issue before we've had a reasonable chance to fix it.
  • Demand payment in exchange for withholding a report. We do not run a paid bug-bounty program and we do not pay crypto ransoms to strangers — that is the exact shakedown this project exists to end. Genuine researchers are always welcome, and we're glad to credit you.

Scope

This policy covers the buckingfugs website and Service at buckingfugs.com. Issues in third-party services we use (such as Stripe or Supabase) should be reported to those vendors directly, though we appreciate a heads-up.

Questions about any of this? We're real people.

Talk to the crew →