socbox

Trust & safety

Reporting abuse, takedowns, and vulnerabilities

socbox.cloud runs a free public code scanner. That means anyone can submit a public Git URL, and anyone can read the resulting scan. This page is where you tell us when something has gone wrong — someone using the scanner against you, a published scan that shouldn't be public, or a security bug in socbox itself.

Report abuse of the public scanner

Use this if someone is using socbox.cloud to recon, harass, or attempt to denial-of-service a system that's yours — for example, repeatedly submitting your organisation's repository to pump load against your Git host, or using socbox findings as a roadmap to attack code you operate.

Email support@socbox.cloud with as much of the following as you have:

We'll acknowledge within one business day and act within five business days. Action ranges from rate-limiting a source IP range, to hiding a permalink from the public feed, to permanently blocking a submitter.

Takedown of a scan permalink

Use this if a published scan at socbox.cloud/scan/<id> contains material you have a legal right to have removed:

Address: support@socbox.cloud with the subject line “Takedown: <permalink>”. Counter-notices follow the same address. We don't require a specific template; we'll come back and ask if anything is missing.

Urgent secrets-leak takedowns are usually same-day. Other valid takedowns are honoured within five business days.

Security vulnerability in socbox itself

Use this if you've found a vulnerability in socbox.cloud — a sandbox escape from the scanner, authentication bypass, server-side request forgery in the submission pipeline, anything that affects the safety of the service or its users.

Email security@socbox.cloud. For sensitive reports, use the PGP key linked from the security page, which also covers scope and safe harbour.

We acknowledge, triage and fix security reports as fast as we can, with critical issues jumping the queue.

Response times

We are deliberately not publishing clock-time commitments until we can staff them. What we can say honestly: security reports and urgent secrets-leak takedowns jump the queue, takedown and abuse requests are handled in the order received, and a secrets-leak takedown moves fastest once you confirm the credential has been rotated.

If you're unsure which address fits, send to support@socbox.cloud and we'll route it.

See also