Security

This policy covers this site and the projects I maintain, listed on the work and projects pages. If a project has its own published security policy, follow that one instead.

Reporting a vulnerability

Email sahithyan.dev@gmail.com with what you found, the steps to reproduce it, and the impact you think it has. Include the project name and, if it applies, the specific URL or endpoint. I read every message myself, there is no triage team.

I do not run a bug bounty. There is no payment for reports, only credit if you want it and a fix.

What to expect

I aim to acknowledge a report within a few days and to keep you updated as I work through it. These are side projects I maintain mostly alone, so timelines vary with how serious the issue is and how much free time I have that week.

Safe harbor

Testing done in good faith, without accessing, modifying, or deleting data that is not yours, without degrading the service for other users, and reported to me privately before any public disclosure, will not result in a legal complaint from me. Please give me a reasonable amount of time to fix the issue before disclosing it publicly.

Out of scope

Automated vulnerability scanner output with no proof of impact, missing security headers or best-practice suggestions with no demonstrated exploit, and reports about third-party services I embed but do not control (analytics, font hosting, and similar).