Security & Responsible Disclosure

Contact

Send security reports to [email protected] with the subject line beginning [security]. The machine-readable contact is published at /.well-known/security.txt.

Scope

Out of scope: third-party hosted dependencies (PostHog, GA4, cal.com, GitHub Pages, Cloudflare) - please report those to their respective programs.

What we ask

What you can expect

Hardening posture

Documented for transparency:

Past disclosures

None published yet. As soon as we close a reported issue with attribution, it lands here.