Security & Responsible Disclosure

Effective: 24 July 2026 · Last updated: 24 July 2026

I build and host my own systems, and I take their security seriously. If you find a vulnerability in any of my sites or services, I want to hear about it — here's how, and the commitments I make to good-faith researchers.

Report a vulnerability
Machine-readable

How I run things

How to report

Email [email protected] with enough detail to reproduce the issue: the URL or service, the steps, and the impact. A proof-of-concept helps. I'll acknowledge receipt, keep you updated, fix validated issues as quickly as I reasonably can, and credit you if you'd like.

Scope

In scope: szczleon.com, app.szczleon.com, files.szczleon.com, and other services clearly operated by me.

Out of scope: social engineering, physical attacks, denial-of-service / volumetric testing, spam, and issues in third-party services I don't control (for example my CDN or email provider — please report those to the provider).

Ground rules for testing

Safe harbor. If you make a good-faith effort to follow this policy, I will consider your research authorized, I won't pursue legal action against you for it, and I'll work with you to understand and fix the issue quickly. If in doubt about whether something is in scope, ask first.

Rewards

I don't run a paid bug-bounty program at this time, but I'm grateful for reports and will happily give public credit to researchers who want it.

Contact

[email protected] · security.txt