Security & Responsible Disclosure
We take the security of our users' data seriously and welcome reports from security researchers.
Reporting a vulnerability
If you believe you have found a security vulnerability, please report it privately to hennadii.shvedko@shvedko.dev. Please include enough detail for us to reproduce the issue. Our machine-readable policy is published at /.well-known/security.txt.
Our commitments
- We will acknowledge your report promptly and keep you informed of our progress.
- We will not pursue legal action against researchers acting in good faith under this policy.
- We will fix verified issues as quickly as is practical and credit reporters who wish to be named.
Scope and ground rules
- Do not access, modify, or delete data that is not your own; use only test accounts you control.
- Do not perform denial-of-service testing, spam, or social-engineering attacks.
- Give us a reasonable time to remediate before any public disclosure.
- Comply with all applicable laws.
Service status
You can check live and historical availability on our status page.