Contact
Security engagements, vulnerability reports, and disclosure coordination all go to the same inbox.
Channels
Broadcast channel for disclosures and write-up announcements. It is not monitored for reports — use email for anything time-sensitive.
Responsible disclosure policy
If you found a security issue in a Dgxcode property or in something I maintain, thank you — please report it privately. I handle reports under coordinated disclosure and I do not treat good-faith research as an attack.
What to include
- The affected URL, endpoint, package, or repository and version
- Step-by-step reproduction, including the request you sent
- The impact: whose data or which action an attacker reaches
- Whether the issue is public or already being exploited, as far as you know
- How you want to be credited, and where to send updates
What I ask you not to do
- Denial-of-service, stress, or brute-force testing
- Social engineering of staff, contractors, or support channels
- Reading, modifying, or deleting data that is not yours — stop at proof of exposure
- Automated scanning at a volume that degrades service for other users
- Publishing details before a fix ships or an agreed disclosure date passes
What you get back
- Acknowledgement within 3 business days of your report
- A triage decision: in scope, out of scope, or duplicate, with reasoning
- A fix timeline and an update when the fix ships
- Credit in the advisory on request, and no legal action for research that stays inside these terms
Safe harbour
Research that follows this policy, stays inside the affected property, and is reported privately before disclosure is considered authorized and good-faith. I will not pursue legal action for it. If a third party is involved, I will say so early rather than let you guess.
Encrypted mail
No PGP key is published yet. If you need confidentiality in transit, say so in your first message and I will arrange a key or an alternate channel before you send details.
Machine-readable policy
This policy is also published as security.txt at /.well-known/security.txt (RFC 9116).