Vulnerability Disclosure Policy

Last updated: August 14, 2026

Our commitment

Antibody Cyber Technology, LLC takes the security of wincyberscan.com and the WinCyberScan™ Windows Security Threat Scanner (WSTS) seriously. We welcome good-faith reports from security researchers. If you discover a vulnerability, please tell us so we can fix it before it can be exploited.

Scope

In scope

  • The wincyberscan.com website and all pages served under that domain
  • The WSTS downloadable executable and its local web dashboard (127.0.0.1:5900)
  • Supporting infrastructure directly operated by Antibody Cyber Technology

Out of scope

  • Denial-of-service (DoS / DDoS) attacks against our servers
  • Social engineering or phishing of our staff
  • Physical attacks against infrastructure
  • Vulnerabilities in third-party libraries or services we use but do not control
  • Reports generated solely by automated scanners with no manual validation
  • Issues with no realistic security impact (e.g. missing security headers on static assets)

How to report

Send a report by email to wayne@antibodynet.net with:

  • A clear description of the vulnerability and its potential impact
  • Steps to reproduce, including any URLs, payloads, or proof-of-concept code
  • Your name or alias (optional) for acknowledgement

Please do not publicly disclose the issue until we have had a reasonable opportunity to investigate and remediate it.

What to expect

MilestoneTarget timeframe
Acknowledgement of your report3 business days
Initial triage and severity assessment7 business days
Remediation of confirmed critical / high issues30 days
Remediation of medium / low issues90 days

We will keep you informed of our progress. If circumstances require more time, we will let you know before the target date passes.

Safe harbor

We will not pursue civil or criminal action against researchers who:

  • Report in good faith following this policy
  • Avoid accessing, modifying, or deleting data beyond what is needed to demonstrate the issue
  • Do not perform destructive testing or exfiltrate data
  • Do not disclose the vulnerability publicly before remediation

We consider good-faith security research conducted under this policy to be authorized access and will not refer such activity to law enforcement.

Recognition

We do not currently offer a bug bounty program. Researchers who report valid, in-scope vulnerabilities will be thanked by name (or alias, as preferred) in our release notes unless they request anonymity.

Contact

Security reports and questions about this policy: wayne@antibodynet.net

← Back to WinCyberScan™