# Security policy for z3tra.com — RFC 9116 # # Found something in one of my projects or on this site? Tell me before you # tell anyone else, and I will credit you. # # NOTE: replace the Contact address, the Encryption fingerprint and the Expires # date below before deploying. `Expires` is mandatory under RFC 9116 and must # be a future date — set a reminder to roll it forward every year. Contact: mailto:contact@z3tra.com Contact: https://z3tra.com/contact Expires: 2027-01-01T00:00:00.000Z Encryption: https://z3tra.com/z3tra-pgp.asc Preferred-Languages: en, fr Canonical: https://z3tra.com/.well-known/security.txt # What I ask # # - Report privately first, and give me a reasonable window to fix it. # - Do not access, modify or exfiltrate data that is not yours. # - No denial of service, no social engineering, no physical attacks. # - Automated scanning is fine; hammering the infrastructure is not. # # What you get # # - An acknowledgement, and an honest timeline. # - Credit in the fix, unless you would rather stay anonymous. # - No legal threats for research conducted in line with the above. # # There is no bug bounty. This is a personal site — the currency is credit.