// Coordinated disclosure
Security Policy
VSec is a volunteer-run community of security people. If you have found a vulnerability in this site or in one of our repositories, we want to hear about it — and we would rather hear about it from you than from someone else.
Report by email
[email protected]Report on GitHub
Open a private advisoryWhat is in scope
- +vsec.dk and any subdomain we operate.
- +The public repositories under github.com/VSecDK, including this website and the CTI League case data.
- +Our Discord bot and the Cloudflare Workers that open content pull requests.
What is not
- –Third-party services we merely link to. Report those to their owners.
- –Scanner output with no working proof of concept, and missing-header findings with no demonstrated impact.
- –Denial of service, spam, or social engineering against our volunteers.
What we ask
Give us a reasonable chance to fix the issue before you publish. Do not access, modify, or delete data that is not yours, and stop as soon as you have demonstrated the problem. Use test data rather than a real member’s account.
We are volunteers, so we cannot promise a service-level agreement. In practice we aim to acknowledge a report within a few days and to agree a disclosure timeline with you from there.
Credit
There is no bug bounty — we have no budget for one. We will credit you by name or handle in the fix and in the release notes unless you would rather stay anonymous.
Machine-readable version:/.well-known/security.txt(RFC 9116)