Security
We take the security of DecryptAds seriously. This page describes how to report
vulnerabilities in good faith. Machine-readable contact details live at
/.well-known/security.txt
(RFC 9116).
Last updated: August 10, 2026.
Vulnerability disclosure
If you believe you have found a security vulnerability in DecryptAds (the web application, REST API, MCP endpoint, or related infrastructure operated by Svart Works Inc.), please report it to security@decryptads.com.
Include enough detail for us to reproduce the issue: affected host or endpoint, steps, impact, and any proof-of-concept that does not destroy data or disrupt other users. We aim to acknowledge reports within a few business days.
No bug bounty (yet). We do not currently operate a paid bug-bounty program. We appreciate responsible reports and will credit researchers who wish to be acknowledged once a fix is available, unless you ask us not to.
Authorized testing
Good-faith security research against DecryptAds systems is permitted under this policy when it stays within the rules below. This is the written authorized testing program referenced in our Terms of Service. Activity outside these bounds is not authorized.
In scope
decryptads.comandwww.decryptads.com(web application)api.decryptads.com(REST API)mcp.decryptads.com(MCP endpoint)
Out of scope / prohibited
- Denial of service, volumetric flooding, or anything that degrades availability for other users
- Social engineering, phishing, or physical attacks against people or offices
- Accessing, modifying, or deleting other users’ data
- Attacking third-party services, customers, or publishers we crawl (report product bugs; do not test third parties)
- Automated scanning that generates abusive traffic or violates rate limits beyond what is needed to demonstrate a finding
Other contacts
- Service abuse (scraping, multi-accounting, ToS violations): abuse@decryptads.com
- Privacy requests: privacy@decryptads.com
- General contact: Contact