// ~/security · responsible disclosure
Security
If you've found a security issue on this site or in Batesian, thank you. Please tell me. This page covers what's in scope, what to expect back, and how I handle reports.
Email security@calbebop.dev, also listed in the security.txt. Encrypted reports aren't required.
in scope
- This website, calbebop.dev.
- Batesian
out of scope
- Third-party services this site relies on. Report those to the provider.
- Social engineering, phishing, or physical attacks.
- Denial-of-service or volumetric testing.
- Automated scanner output with no proof of exploitability.
- Issues on pages with no sensitive action, or header gaps I have deliberately traded off.
This site has no user accounts and collects no personal data.
I'm one person doing this on evenings, so timelines flex, but the target is:
- Acknowledge your report within 48 hours.
- Initial assessment within 7 days.
- A fix or coordinated disclosure within 90 days, the Project Zero convention.
Send a writeup with reproduction steps and I'll keep you in the loop as I work it.
Acting in good faith on a real issue, without degrading the site or its users, I won't pursue legal action. Don't exfiltrate other people's data, don't linger in places you shouldn't, and stop once you've shown the issue.
There's no cash bounty. This is a personal site and a free tool. How I'll thank reporters is still being worked out. If you send something real, I'll make sure you're credited properly and on your terms.