ASIScan is built and supported by a small team, which has one advantage worth stating: the person who answers your email is the person who wrote the rule you're asking about.
Two things resolve most issues faster than we can reply:
npm test. Seventeen tests ship with the Software. If
they pass, your install is sound and the problem is likely configuration or a rule
question. If they fail, paste the failure into your email — that tells us almost
everything.| Issue | What to send | Typical turnaround |
|---|---|---|
| Install or build failure | Your Node version (node -v), OS, and the full error output |
1 business day |
| False positive | The rule ID (e.g. ASI05) and a redacted snippet of the triggering line | 2 business days; fix usually in the next v1.x |
| False negative — it missed something real | The risk ID and a minimal example of the pattern it should have caught | 2 business days. These are the most valuable reports we get. |
| Licence scope question | What you want to do, and how many codebases or developers are involved | 1 business day |
| Refund | Email from the address you purchased with, within 30 days. No justification needed. | Processed within 5 business days |
| Invoice or tax documentation | Your Stripe receipt and the business details you need on the invoice | 2 business days |
We don't want it, we don't need it, and holding it creates risk for both of us. A rule ID and a redacted one-line snippet is enough to diagnose almost any finding.
Never send credentials, API keys, tokens, or customer data. If a finding involves a real secret, rotate it first — then tell us about the pattern, not the value.
Being straight about this so expectations are right from the start:
If you find a vulnerability in the Software, email hello@protocol42.io with SECURITY in the subject line. Please give us a reasonable window to investigate and ship a fix before public disclosure — we will acknowledge within two business days, keep you updated, and credit you in the release notes if you'd like.
We won't threaten legal action against anyone who reports a genuine vulnerability in good faith.
Your licence includes all v1.x updates at no charge. Rules move as OWASP publishes and as false-positive reports come in, so updating is worth doing periodically. We'll email licence holders when a release contains a meaningful rule change.
Protocol 42 · Ontario, Canada