Abuse & contact

Seeing our traffic? Requests carry the user agent SecureIndie-probe and, for live proofs, an X-SecureIndie-Probe header with the scan id. Every probe runs under a per-host rate limit of about one request a second.
We don't change your data. Most probes are read-only GETs. Our only messages are a few short test prompts to AI endpoints, to prove whether strangers can use them. If your app saves chat history, they'll appear there. (They are POST requests: at most two per AI endpoint, at most three endpoints per scan.) Paid audits also run well-known detection templates with login attempts and exploit payloads excluded. We never change or delete anything in your app or database.
Stop us immediately. Email abuse@secureindie.com with your hostname. We add it to the kill-switch (no further probes) and reply with the scan ids involved. Operators with an API key can pause a host themselves via POST /v1/safety/pause.
Report a vulnerability in SecureIndie. Same address. We do not run bug bounties yet, but we credit reporters and fix fast.