Security
Last updated: 25 September 2026
We welcome reports of security vulnerabilities in Profit Scanner. This page is the policy referenced by our security.txt.
How to report
Email [email protected] with:
- a clear description of the issue and its impact;
- steps to reproduce (a proof of concept);
- the affected URL or asset;
- the name you want to be credited with, if any.
We aim to send a first reply within 7 days (as stated in security.txt). Please give us reasonable time to fix the issue before you disclose it publicly.
Scope
- profit-scanner.com and app.profit-scanner.com;
- the published Chrome extension (Profit Scanner – Amazon FBA Deal Analyzer).
Out of scope
- social engineering of our team, and physical attacks;
- denial of service;
- automated scanner output without a manual validation;
- findings that are already public (check with tools such as SSL Labs or securityheaders.com first).
Rules
- Test only with accounts you own, and never access, change or delete other users' data. If you reach someone else's data by accident, stop, and tell us what you saw.
- Do not degrade the service for other users.
We do not run a formal bug bounty programme. We review every report, and we may offer a thank-you at our discretion for valid, previously unknown findings that lead to a fix.