  // SECURITY# The bug bounty program is closed

 Scrapfly no longer operates a public bug bounty program. Unsolicited vulnerability reports are not triaged and are not eligible for any reward. Security testing of Scrapfly is contracted to a private penetration-testing partner and reviewed by our external compliance auditor.

**Closed since:** May 2026

 

 ---

 ## Why we closed it

 The program stopped producing security value. Submissions became dominated by machine-generated reports: long, confident write-ups with no reproducible finding behind them. Every one of them still had to be read, reproduced and dismissed by the same engineers who build the platform, and the volume turned triage into the most expensive line of our security budget while finding nothing.

 We would rather spend that budget on testing that is scoped, repeatable and accountable: a partner who tests the systems we ask them to test, on a schedule, with findings tied to a named engagement, and an auditor who verifies the findings were actually remediated.

 

 

 

  ## How security testing works now

 PENETRATION TESTING### A contracted partner

 Testing is performed by a private security firm under NDA, on a defined scope and cadence, against systems we nominate. Their report names the tester, the window and the method.

 



 

 VERIFICATION### An external auditor

 Findings, severities and remediation are tracked and reviewed by our external compliance auditor as part of our SOC 2 Type II and ISO 27001 programs. Closing a finding requires evidence, not an assertion.

 



 

 ENGINEERING### Internal review

 Security review stays part of how changes ship here, and the evidence of it goes to the auditor rather than to a public queue.

 



 

 

 

  ## Testing is no longer authorized

 The previous program granted authorization to test `https://scrapfly.io` and `https://api.scrapfly.io`. That authorization is withdrawn. No Scrapfly domain, property or API is in scope for unsolicited security testing.

 Scanning, probing, exploiting, or attempting to reach data that is not yours is unauthorized use of the service under our [Terms of Service](https://scrapfly.io/terms-of-service), and traffic of that shape is handled as abuse.

## If you are a customer or a prospect

 Audit reports, certifications and security questionnaires for a vendor review are published on our [security and compliance page](https://scrapfly.io/compliance) and in our trust portal. That is the fastest route to whatever your security team needs from us.

## If you believe you found a critical issue anyway

 Our RFC 9116 contact stays live at [/.well-known/security.txt](https://scrapfly.io/.well-known/security.txt) and reaches legal\[at\]scrapfly.io. We read what arrives there, with no reward, no bounty, no response commitment, and no permission to test in order to produce a report. Send a finding you came across, not one you went looking for.

 [  Security &amp; compliance ](https://scrapfly.io/compliance)