ExoPriors Scry

ExoPriors · Legal

Security & Vulnerability Disclosure

Effective 2026-09-10

If you have found a security problem in something we run, we want to hear about it from you first. Write to [email protected] with enough detail to reproduce: the host and endpoint, the request, what you observed, and what you expected. Encrypt with our OpenPGP key (fingerprint 2F68 CFB1 3EFA AD78 D666 5A80 2C61 DA50 4720 2629) if the report is sensitive. This page is the Policy field of /.well-known/security.txt on every host we serve.

Scope

Everything ExoPriors operates: the web hosts (exopriors.com, scry.io, and the sibling product sites served from the same estate), the API at api.scry.io, the MCP door at mcp.scry.io, the console, billing, and the OAuth flow. We are most interested in anything that crosses a boundary: reading or altering another account's data, queries, keys, or balance; executing beyond the read-only SQL surface; escaping a sandbox; bypassing authentication, rate limits, or metering; and leaked credentials. If you find an ExoPriors or Scry API key or secret in a public place, send it to us and do not use it.

Out of scope: the third-party sites whose public material we index (report those to their operators); volumetric denial of service; social engineering of our people; physical attacks; reports from automated scanners with no demonstrated impact; and the ordinary cost of a metered service — spending credit on queries is usage, not a vulnerability.

Rules of engagement

Test against accounts you own. If you reach data that is not yours, stop at the proof — do not read further, copy, alter, or share it — and tell us. Do not degrade the service for others; the API is shared and metered, so keep your traffic to what a proof requires. Do not spam, phish, or social-engineer. Give us time to fix before you publish: we ask for 90 days from your report, and we will tell you if we need less.

Safe harbor

Research conducted in good faith under this policy is authorized. We will not pursue civil action or refer it to law enforcement, and we consider it compliant with our Terms of Service. If a third party brings action against you for activity that followed this policy, we will say so. If you are unsure whether something is covered, ask before you test.

What to expect

We acknowledge reports within three business days and give a triage verdict within ten. We keep you informed as we fix, and we credit researchers by name on request once a fix has shipped. We do not run a paid bounty program today.