Security

Vulnerability disclosure

We take reports of security issues in AbuseGraph products and infrastructure seriously. Thank you for helping keep customers safe.

How to report

Email hello@abusegraph.com with a clear description, impact, and steps to reproduce. Include affected URLs or API paths when relevant.

  • Do not access or modify customer data.
  • Do not run destructive testing against production.
  • Never send live API keys or secrets in the report body.
  • Give us a reasonable window before public disclosure.

Scope

In scope: abusegraph.com, api.abusegraph.com, the browser SDK, and related public APIs documented at /docs. Out of scope: social engineering, physical attacks, and third-party services we do not operate.

Machine-readable

RFC 9116 /.well-known/security.txt