Legal
Security Policy
How to report a TCP Viewer security vulnerability and the rules for good-faith research.
Last updated September 8, 2026
Proxyman LLC welcomes reports that help us protect TCP Viewer users. This policy explains how to report a vulnerability in TCP Viewer, the TCP Viewer website, or services operated by us.
1. Report privately
Email tcpviewer@proxyman.com with the subject TCP Viewer Security Report. Do not open a public GitHub issue for an undisclosed vulnerability.
Include what you can:
- The affected app version, URL, endpoint, or component.
- The impact and who could be affected.
- Clear reproduction steps or a minimal proof of concept.
- Relevant logs or screenshots with personal data, packet contents, access links, credentials, and license keys removed.
- Whether you have disclosed the issue to anyone else and your proposed disclosure date.
- A way to contact you for follow-up.
Do not send a working exploit against production, real customer data, a real license key, a License Manager link, or an unredacted packet capture unless we first agree on a safe transfer method.
2. Scope
This policy covers:
- Official TCP Viewer macOS releases published by Proxyman LLC.
- Source in the ProxymanApp/TCPViewer repository.
tcpviewer.proxyman.comandapi-tcpviewer.proxyman.com.- TCP Viewer licensing, checkout integration, downloads, updates, and License Manager services operated by Proxyman LLC.
Third-party services, websites, and applications are outside our authority. This includes Stripe, Sentry, GitHub, hosting providers, email providers, and Apple services. Report a vulnerability in those systems to the relevant provider.
3. Research rules
To stay within this policy:
- Use your own account, devices, data, and license entitlement.
- Test only what is necessary to confirm a vulnerability and its impact.
- Stop immediately if you encounter another person's data, credentials, license details, packet contents, or confidential information. Tell us what happened without retaining or sharing the data.
- Do not download, alter, destroy, or disclose data that is not yours.
- Do not create persistence, move laterally, install malware, or use a vulnerability to access another system.
- Do not use denial of service, traffic flooding, spam, automated high-volume scanning, social engineering, phishing, physical intrusion, or attacks on employees or providers.
- Do not disrupt the service or degrade it for other users.
- Give us a reasonable opportunity to investigate and fix a confirmed issue before public disclosure. Coordinate disclosure timing with us.
- Follow applicable law and this policy.
The GPL permits research and modification of GPL-covered code. These rules apply to testing our production services and handling data, not to rights granted by the GPL for software copies.
4. Safe harbor
If you make a good-faith effort to follow this policy, we will consider your research authorized under this policy and will not start legal action against you for that research. If a third party starts legal action based on research that followed this policy, we will state that your research complied with our policy.
This safe harbor does not authorize activity against third-party systems, waive another person's rights, bind independent third parties, or excuse a violation of law. If you are unsure whether a test is permitted, contact us before continuing.
5. What we will do
We will make a reasonable effort to:
- Acknowledge the report and give you a contact for follow-up.
- Triage the issue, ask for missing details, and keep you informed of material progress.
- Work with you on a reasonable disclosure schedule based on impact and fix complexity.
- Credit you if you request credit and if doing so is lawful and appropriate.
This is not a bug-bounty program. We do not promise payment, rewards, or a particular response or fix time. Any reward requires a separate written agreement.
6. Security and privacy incidents
This policy is for product vulnerabilities. If you believe your license, License Manager link, personal data, or support account has been exposed, email tcpviewer@proxyman.com promptly and explain that the message concerns an active security or privacy incident.
7. Contact
Security reports: tcpviewer@proxyman.com
Preferred language: English
Proxyman LLC, 1209 Orange Street, Wilmington, Delaware 19801, United States