Security

Security

Last updated: 25 September 2026

We welcome reports of security vulnerabilities in Profit Scanner. This page is the policy referenced by our security.txt.

How to report

Email [email protected] with:

  • a clear description of the issue and its impact;
  • steps to reproduce (a proof of concept);
  • the affected URL or asset;
  • the name you want to be credited with, if any.

We aim to send a first reply within 7 days (as stated in security.txt). Please give us reasonable time to fix the issue before you disclose it publicly.

Scope

  • profit-scanner.com and app.profit-scanner.com;
  • the published Chrome extension (Profit Scanner – Amazon FBA Deal Analyzer).

Out of scope

  • social engineering of our team, and physical attacks;
  • denial of service;
  • automated scanner output without a manual validation;
  • findings that are already public (check with tools such as SSL Labs or securityheaders.com first).

Rules

  • Test only with accounts you own, and never access, change or delete other users' data. If you reach someone else's data by accident, stop, and tell us what you saw.
  • Do not degrade the service for other users.

We do not run a formal bug bounty programme. We review every report, and we may offer a thank-you at our discretion for valid, previously unknown findings that lead to a fix.