Aether Staticsecurity.txt

Security reporting

Report vulnerabilities privately so the issue can be investigated, corrected, and disclosed in a way that protects site visitors and downstream users.

Policy version 1.0Updated July 9, 2026RFC 9116 file
Private reporting address

[email protected]

Include a clear description, affected URL, reproduction steps, observed impact, and any supporting request or response details. Remove credentials and personal information before sending.

mailto:[email protected]
Response targets

Coordinated handling

ReceiptTarget: 1 business day
Initial assessmentTarget: 3 business days
Status updatesAt meaningful investigation milestones

Targets are goals, not guarantees. Complex reports may require additional time.

In scope

aetherstatic.com pages, public metadata endpoints, security contact handling, and issues that materially affect confidentiality, integrity, or availability.

Out of scope

Automated scanner output without evidence, missing non-security headers without impact, social engineering, denial-of-service testing, and third-party services not controlled by the project.

Safe testing

Use your own systems and data, keep request volume low, stop if testing risks availability, and do not access or alter information belonging to others.

Disclosure

Allow reasonable time to investigate and deploy a correction before publishing details. Credit can be provided when requested and appropriate.

Acknowledgments

Reporter recognition

No public acknowledgments are listed yet. With permission, validated reports may be credited after remediation and coordinated disclosure.

Availability reports

Check current service state first.

For outages or degraded public resources without a security impact, check the status page and use the general project mailbox.