Legal
Security
Responsible disclosure of security issues affecting this site.
Responsible disclosure
If you've found a security issue affecting this site or its supporting infrastructure, reporting it directly and privately is genuinely appreciated — please don't open a public GitHub issue or post about it before there's been a chance to look into it and ship a fix.
Scope
In scope:
- ashishvrm.com and its subdomains (the public site, the API, the CMS admin panel).
- The contact-form and newsletter submission pipeline.
- Authentication, session handling, and access-control logic on anything publicly reachable.
Out of scope:
- Denial-of-service or load-testing against production infrastructure.
- Social engineering directed at the site owner or any third-party provider's support staff.
- Physical access attempts.
- Spam or abuse of the contact form / newsletter signup that isn't demonstrating an actual security vulnerability.
- Findings that require an already-compromised or physically-accessed device.
How to report
Email the security contact below with:
- A clear description of the issue and its potential impact.
- Steps to reproduce it, or a proof-of-concept if one exists.
- Any tooling or automated scanners used (helps set expectations on noise vs. signal).
A PGP key isn't currently published — if the report contains sensitive detail you'd rather not send in plaintext, say so and a secure channel can be arranged.
What to expect
- Acknowledgement of a genuine report within 3 business days.
- Honest, direct communication about whether it's confirmed, its severity, and a rough timeline for a fix — no scripted stalling.
- Credit, publicly if you'd like it, once the fix has shipped. There's no paid bug bounty program at this time, but a genuine, responsibly disclosed finding is always acknowledged.
Safe harbor
Reports made in good faith, within the scope above, and without accessing, modifying, or exfiltrating data beyond what's needed to demonstrate the issue, won't be treated as unauthorised access. Reasonable, well-intentioned security research is welcome, not punished.
This policy pairs with the machine-readable `/.well-known/security.txt`, which points at the same contact address.