[email protected]
Include a clear description, affected URL, reproduction steps, observed impact, and any supporting request or response details. Remove credentials and personal information before sending.
mailto:[email protected]Report vulnerabilities privately so the issue can be investigated, corrected, and disclosed in a way that protects site visitors and downstream users.
Include a clear description, affected URL, reproduction steps, observed impact, and any supporting request or response details. Remove credentials and personal information before sending.
mailto:[email protected]Targets are goals, not guarantees. Complex reports may require additional time.
aetherstatic.com pages, public metadata endpoints, security contact handling, and issues that materially affect confidentiality, integrity, or availability.
Automated scanner output without evidence, missing non-security headers without impact, social engineering, denial-of-service testing, and third-party services not controlled by the project.
Use your own systems and data, keep request volume low, stop if testing risks availability, and do not access or alter information belonging to others.
Allow reasonable time to investigate and deploy a correction before publishing details. Credit can be provided when requested and appropriate.
No public acknowledgments are listed yet. With permission, validated reports may be credited after remediation and coordinated disclosure.
For outages or degraded public resources without a security impact, check the status page and use the general project mailbox.