// ~/security · responsible disclosure
Security
If you've found a security issue on this site or in Batesian, thank you. Please tell me. This page covers what's in scope, what to expect back, and how I handle reports.
REPORTING
Email security@calbebop.dev, also listed in the security.txt. Encrypted reports aren't required.
SCOPE
in scope
- This website, calbebop.dev.
- Batesian
out of scope
- Third-party services this site relies on. Report those to the provider.
- Social engineering, phishing, or physical attacks.
- Denial-of-service or volumetric testing.
- Automated scanner output with no proof of exploitability.
- Issues on pages with no sensitive action, or header gaps I have deliberately traded off.
This site has no user accounts and collects no personal data.
WHAT TO EXPECT
I'm one person doing this on evenings, so timelines flex, but the target is:
- Acknowledge your report within 48 hours.
- Initial assessment within 7 days.
- A fix or coordinated disclosure within 90 days, the Project Zero convention.
Send a writeup with reproduction steps and I'll keep you in the loop as I work it.
SAFE HARBOR
Acting in good faith on a real issue, without degrading the site or its users, I won't pursue legal action. Don't exfiltrate other people's data, don't linger in places you shouldn't, and stop once you've shown the issue.
REWARDS & CREDIT
There's no cash bounty. This is a personal site and a free tool. How I'll thank reporters is still being worked out. If you send something real, I'll make sure you're credited properly and on your terms.