Vulnerability Disclosure Policy
Effective date: September 30, 2026
EchoThread is operated by VectraSEO LLC. We welcome good-faith reports of security vulnerabilities in EchoThread. This page explains how to report one, what is in scope, and the safe harbor we give researchers who follow it. We do not run a paid bug bounty program.
1. How to report
Email security@echothread.io. Please include:
- the affected URL, endpoint, or component;
- steps to reproduce, or a proof of concept that is as small as possible;
- the impact you believe the issue has; and
- how you would like to be credited, if at all.
Please do not post details publicly, or open a public issue, before we have had a chance to fix the problem. Our contact details are also published in machine-readable form at /.well-known/security.txt.
2. No bounty
We cannot offer monetary rewards, and we do not accept reports whose main purpose is to ask for payment. Once an issue is fixed, we will credit you if you want us to.
3. What to expect
- We aim to acknowledge reports within 5 business days.
- We will tell you whether we have confirmed the issue and keep you updated until it is resolved.
- We ask for up to 90 days from your report to fix an issue before you disclose it publicly. If we need longer, or you need to disclose sooner, please talk to us first.
4. Scope
In scope:
- echothread.io and www.echothread.io;
- api.echothread.io; and
- the embed widget served from cdn.echothread.io.
Out of scope:
- other VectraSEO LLC products and domains not listed above;
- third-party services we rely on, such as AWS, DigitalOcean, Stripe, and sign-in providers (report those to the provider);
- denial-of-service or volumetric testing, spam, and social engineering or phishing of our staff or users;
- physical attacks;
- missing security headers, SPF/DKIM/DMARC settings, or version banners without a demonstrated, exploitable impact;
- automated scanner output without a working proof of concept; and
- vulnerabilities that require a rooted or jailbroken device, or an already compromised account or browser.
5. Good-faith research
To stay within this policy, please:
- test only against accounts and data you own or have permission to use, and stop as soon as you have shown the issue exists;
- not access, change, delete, or keep other people's data. If you encounter personal data, stop and report it to us;
- not disrupt the Service or degrade it for other users;
- not use an exploit to move laterally, install persistence, or pivot to other systems; and
- keep the details private until the issue is fixed or 90 days have passed, whichever comes first.
6. Safe harbor
If you make a good-faith effort to follow this policy, we will consider your research to be authorized under our Terms of Service, and we will not initiate legal action against you, or ask law enforcement to do so, for that research. If your testing would otherwise break a restriction in the Terms (for example, the prohibition on probing or scanning the Service), we waive that restriction for the limited purpose of this research. We will not bring a claim against you for circumventing technical controls on the systems in scope.
This safe harbor applies only to EchoThread systems and to VectraSEO LLC's own rights. We cannot authorize testing of, or bind, third parties such as our hosting and service providers, and other users' rights are not affected. This policy is not an offer of a contract or of any payment, and it does not override applicable law. If a third party or authority starts legal action over research that followed this policy, we will say that it was authorized. Research that does not follow this policy, or that is done in bad faith, is not covered.