Security policy

Responsible Disclosure Program

Disclosure Guidelines

We are dedicated to maintaining the privacy of the Scrimba students and security of our services. We therefore warmly welcome security researchers who want to help us improve our products and services. If you discover a security vulnerability, please give us the chance to fix it by emailing us at security@scrimba.com. Publicly disclosing a security vulnerability without informing us first puts the rest of the community at risk. When you notify us of a potential problem, we will work with you to make sure we understand the scope and cause of the issue.

Thank you for your efforts and interest in making the community safer!

Bounty Program

We do not respond well to begging for bounties, sending repeated direct emails to our team, and other activities best known as "Bounty begging". We will not reward such activities.

But we award security serious researchers cash and prizes for reporting vulnerabilities. Please email security@scrimba.com with a short and clear description that we can investigate.

If you would like to be eligible for a bounty, please read this carefully.

In-scope Services

Only the following services are in-scope:

  • "scrimba.com"

Third party applications and websites that are used by Scrimba (i.e. Discord, HelpScout, etc.) are outside of scope and issues should be reported directly to the owners of those services.

Out-of-scope Issues

The following types of reports/attacks are out of scope. Do not attempt them:

  • Reports about any service not listed under "In-Scope Services," above
  • DOS attacks
  • Brute force attacks
  • Physical vulnerabilities
  • Social engineering attacks, including but not limited to:
    • phishing
    • email auth (SPF, DKIM, etc.)
    • hyperlink injection in emails
  • Functional, UI and UX bugs and spelling mistakes
  • CSRF on forms that are available to anonymous users (e.g., signup, login)
  • Self-XSS and issues exploitable only through self-XSS
  • Clickjacking and issues only exploitable through clickjacking
  • Descriptive error messages (e.g. stack traces, application or server errors)
  • HTTP 404 codes/pages or other HTTP error codes/pages
  • Disclosure of known public files or directories, (e.g. robots.txt)
  • Presence of application or web browser "autocomplete" or "save password" permission
  • User enumeration on login
  • Absence of rate limits

PGP

Encrypting your email is not required.