Security

Security & vulnerability reporting

This page explains how we protect data and how you can report security issues responsibly.

Current practices

Report a vulnerability

If you find a vulnerability, contact us privately first (please do not disclose publicly before we can respond). Include clear reproduction steps, impact, and a safe proof of concept.

Scope

In scope: this web application, this site’s public APIs, form submissions, and payments integrated on this domain.

Out of scope: DoS/DDoS, social engineering of staff, aggressive automated scanning, or issues on third-party services outside our control.

Data

The site may store order data, contact form submissions, and admin accounts on your hosting. Order/support magic links are secrets — do not share them publicly.

Updated: 2026-08-03 · /.well-known/security.txt