Security

Report a vulnerability

Email us. Do not disclose the issue publicly until we have had a chance to fix it.

Contact

security@plainscrape.com

Machine-readable contact: /.well-known/security.txt (RFC 9116).

Scope

In: this website, the public API, and the signed-in dashboard. Reports about unsafe fetching of internal or private network addresses are in scope.

Out: attacking websites that are not ours by sending them through Plainscrape; social engineering our staff or customers; physical security; denial-of-service that disrupts paying users.

What we ask

  • Write to the address above before you publish.
  • Give enough detail to reproduce. A URL, the request, and what you observed is enough.
  • Do not access other customers’ data, and stop if you find you can.
  • Do not use the finding to keep a foothold in the system.

Good-faith research that follows this page will not be treated as a hostile act by us. That is not a licence to break the law.

What is already in place

  • Submits are checked against a public-URL gate (SSRF). Private, loopback, and link-local addresses are refused before the extraction box sees them.
  • API keys are stored hashed (SHA-256) and shown once. There is no “show key again”.
  • What we keep: account and job metadata; the instruction truncated to 2,000 characters in operational events; an output sample capped at 4,000 bytes. Events are kept for 90 days by default. There is no nightly delete of accounts or jobs. Email hello@plainscrape.com from the account address to request deletion — see privacy.
  • What goes upstream: the URL and instruction you submit. The extraction box fetches the page. We do not send your API key to it.

There is no SOC 2 report. That is a missing artefact, not a claim that the controls above are absent.

What we do not promise

There is no bug bounty. There is no response-time SLA. We read every report sent to the address above.