Report a vulnerability
Email us. Do not disclose the issue publicly until we have had a chance to fix it.
Contact
Machine-readable contact: /.well-known/security.txt (RFC 9116).
Scope
In: this website, the public API, and the signed-in dashboard. Reports about unsafe fetching of internal or private network addresses are in scope.
Out: attacking websites that are not ours by sending them through Plainscrape; social engineering our staff or customers; physical security; denial-of-service that disrupts paying users.
What we ask
- Write to the address above before you publish.
- Give enough detail to reproduce. A URL, the request, and what you observed is enough.
- Do not access other customers’ data, and stop if you find you can.
- Do not use the finding to keep a foothold in the system.
Good-faith research that follows this page will not be treated as a hostile act by us. That is not a licence to break the law.
What is already in place
- Submits are checked against a public-URL gate (SSRF). Private, loopback, and link-local addresses are refused before the extraction box sees them.
- API keys are stored hashed (SHA-256) and shown once. There is no “show key again”.
- What we keep: account and job metadata; the instruction truncated to 2,000 characters in operational events; an output sample capped at 4,000 bytes. Events are kept for 90 days by default. There is no nightly delete of accounts or jobs. Email hello@plainscrape.com from the account address to request deletion — see privacy.
- What goes upstream: the URL and instruction you submit. The extraction box fetches the page. We do not send your API key to it.
There is no SOC 2 report. That is a missing artefact, not a claim that the controls above are absent.
What we do not promise
There is no bug bounty. There is no response-time SLA. We read every report sent to the address above.