Trust Center
Vulnerability Disclosure Policy
Dino welcomes reports of security vulnerabilities in our products and infrastructure. We work with researchers in good faith to verify and remediate valid issues.
Scope
In scope:
- The Dino web application and console
- The Dino API
- The Dino runner software
Out of scope:
- Customer APIs and customer systems. Do not test a customer's target through Dino as a way to research Dino.
- Third-party services Dino uses. Report those to the third party.
- Denial-of-service testing, social engineering, and physical attacks.
How to report
Email security@usedino.dev with a description of the issue, steps to reproduce, and the potential impact. For sensitive reports, encrypt your message with our PGP key, published at https://usedino.dev/.well-known/pgp-key.txt (fingerprint B3D4 CC85 F699 A262 8E60 CD78 6268 F5B1 37C8 CF07). Our security.txt is PGP-signed, so you can verify its authenticity against the same key.
Safe harbor
If you make a good-faith effort to comply with this policy during your research, Dino will not pursue or support legal action against you for that research. This safe harbor does not extend to actions that violate this policy, access or exfiltrate data beyond what is necessary to demonstrate a vulnerability, degrade the service, or affect other customers.
What we ask
- Give us a reasonable time to investigate and remediate before any public disclosure.
- Do not access, modify, or delete data that is not yours.
- Do not run automated scanning that degrades the service.
- Act only against in-scope systems.
security.txt
Published at https://usedino.dev/.well-known/security.txt, PGP-signed, so you can verify it against our public key:
Contact: mailto:security@usedino.dev
Encryption: https://usedino.dev/.well-known/pgp-key.txt
Expires: 2027-06-22T00:00:00.000Z
Preferred-Languages: en
Canonical: https://usedino.dev/.well-known/security.txt
Policy: https://usedino.dev/vulnerability-disclosureFor general questions, visit our Contact page.