Security

We take the security of DecryptAds seriously. This page describes how to report vulnerabilities in good faith. Machine-readable contact details live at /.well-known/security.txt (RFC 9116).

Last updated: August 10, 2026.

Vulnerability disclosure

If you believe you have found a security vulnerability in DecryptAds (the web application, REST API, MCP endpoint, or related infrastructure operated by Svart Works Inc.), please report it to security@decryptads.com.

Include enough detail for us to reproduce the issue: affected host or endpoint, steps, impact, and any proof-of-concept that does not destroy data or disrupt other users. We aim to acknowledge reports within a few business days.

No bug bounty (yet). We do not currently operate a paid bug-bounty program. We appreciate responsible reports and will credit researchers who wish to be acknowledged once a fix is available, unless you ask us not to.

Authorized testing

Good-faith security research against DecryptAds systems is permitted under this policy when it stays within the rules below. This is the written authorized testing program referenced in our Terms of Service. Activity outside these bounds is not authorized.

In scope

Out of scope / prohibited

Other contacts