·····

// ~/security · responsible disclosure

Security

If you've found a security issue on this site or in Batesian, thank you. Please tell me. This page covers what's in scope, what to expect back, and how I handle reports.

~/security/report REPORTING

Email security@calbebop.dev, also listed in the security.txt. Encrypted reports aren't required.

~/security/scope SCOPE

in scope

  • This website, calbebop.dev.
  • Batesian

out of scope

  • Third-party services this site relies on. Report those to the provider.
  • Social engineering, phishing, or physical attacks.
  • Denial-of-service or volumetric testing.
  • Automated scanner output with no proof of exploitability.
  • Issues on pages with no sensitive action, or header gaps I have deliberately traded off.

This site has no user accounts and collects no personal data.

~/security/sla WHAT TO EXPECT

I'm one person doing this on evenings, so timelines flex, but the target is:

  • Acknowledge your report within 48 hours.
  • Initial assessment within 7 days.
  • A fix or coordinated disclosure within 90 days, the Project Zero convention.

Send a writeup with reproduction steps and I'll keep you in the loop as I work it.

~/security/safe-harbor SAFE HARBOR

Acting in good faith on a real issue, without degrading the site or its users, I won't pursue legal action. Don't exfiltrate other people's data, don't linger in places you shouldn't, and stop once you've shown the issue.

~/security/credit REWARDS & CREDIT

There's no cash bounty. This is a personal site and a free tool. How I'll thank reporters is still being worked out. If you send something real, I'll make sure you're credited properly and on your terms.