Skip to main content
ScamWatch
← Back to Command Center

Security Policy

Last Updated: July 1, 2026


1. Responsible Disclosure

We take system security seriously. If you discover a vulnerability or security flaw, please report it privately to our security team at security@scamwatch.org. We request that you do not disclose the vulnerability publicly until we have had reasonable time to evaluate and remediate it.

2. Safe Harbor

We support safety research. If you perform vulnerability research in good faith compliance with this policy, we will not initiate legal action against you or request law enforcement to investigate.

3. Data Handling & Stripping

ScamWatch is built to protect your identity. All uploaded text is checked on the client and server to strip personal identifiers (such as SSNs, credit card numbers, or passwords) before saving. When users upload screenshots, ScamWatch strips hidden EXIF metadata before storage or review when technically possible.

4. What You Should & Should Not Submit

✅ What to submit:

  • Suspicious text message narratives or copy-pasted scam scripts.
  • Links (URLs) contained in suspicious messages.
  • Phone numbers or emails that initiated the contact.

❌ What NOT to submit:

  • Your own passwords, credit card numbers, CVVs, or bank PINs.
  • Your full Social Security Number (SSN).
  • Any other sensitive personal document scans.

5. Reporting Abuse

If you find that an entity page displays your private, personal number or email (due to someone incorrectly submitting it), please notify us immediately at abuse@scamwatch.org. We will review the submission and redact it within 24 hours.