🔒 Vulnerability Disclosure Policy

Version: 1.0 | Last Updated: 09.09.2025

1. Commitment to Security

Andri.is is committed to the security of my services and data. I value the contributions of the independent security research community in helping me maintain a secure environment. If you believe you have discovered a security vulnerability, I encourage you to report it to me responsibly and in accordance with this policy.

2. Authorization and Safe Harbor

I consider security research and vulnerability disclosure activities conducted in accordance with this policy to be "authorized" conduct. I will not pursue civil or criminal action, or notify law enforcement, for accidental or good-faith violations of this policy. I waive any potential claims against you for circumventing technological measures used to protect the systems in scope of this policy. If legal action is initiated by a third party against you for activities that were conducted in accordance with this policy, I will make this authorization known.

3. Scope

In-Scope Systems:

Out-of-Scope Systems:

Any third-party systems or services used by Andri.is (e.g., hosting provider infrastructure, external APIs, integrated SaaS platforms). Vulnerabilities discovered in these systems should be reported to the respective vendor according to their disclosure policy.

Out-of-Scope Vulnerabilities:

The following issues are considered out of scope:

4. Rules of Engagement

When conducting your research, you must not:

You must:

5. Reporting Process

How to Report:

Please submit your findings via email to security@andri.is. For machine-readable discovery of this policy and contact information, please refer to the /.well-known/security.txt file on this domain.

What to Include:

To help me validate and prioritize your submission, please include the following in your report:

Reports may be submitted anonymously.

6. Our Response Commitment

When you choose to share your contact information, I commit to the following:

7. Recognition

I do not offer monetary rewards (bug bounties) for reported vulnerabilities. However, for valid reports that are submitted in accordance with this policy, I am happy to provide public recognition on a "Hall of Fame" page. Please let me know if you would like to be acknowledged and, if so, under what name or handle. By default, you will not be mentioned if you do not provide explicit permission.

8. Policy Governance

This policy may be updated at any time. Please refer to the "Last Updated" date at the top of this document for the current version. For any questions regarding this policy, please contact security@andri.is.

💬 AI Assistant