-
Change default credentials before deploying publicly:
- Dashboard login:
snape/snapescape(change insnapescape_api/auth.pyor use env) SNAPESCAPE_JWT_SECRETin.envSNAPESCAPE_VAULT_KEYin.env
- Dashboard login:
-
Never commit:
.env(gitignored)config/vault.json(gitignored)- Scan reports with real target data
- API keys (OpenAI, Shodan, etc.)
-
Authorized testing only — only scan targets you own or have written permission to test.
If you find a security issue in SNAPESCAPE itself, report it privately to the repository owner.