TRUST & SAFETY
Security & Responsible Disclosure
We take the safety of this site and the privacy of everyone who uses it seriously. If you have found a security vulnerability, we want to hear from you — and we commit to working with good-faith researchers fairly.
Report a vulnerability
Please email security@honestapologist.com with a clear description of the issue and the steps to reproduce it. Where possible, include the affected URL, a proof-of-concept, and what an attacker could achieve. We aim to acknowledge reports within a few business days.
Our commitment to you (safe harbor)
If you make a good-faith effort to comply with this policy during your research, we will consider your testing authorized, we will not pursue or support legal action against you, and we will work with you to understand and resolve the issue promptly. We are grateful for the work of the security community and will happily credit you once a fix has shipped, if you would like.
Guidelines
Please do:
- Give us a reasonable time to investigate and fix an issue before disclosing it publicly.
- Only interact with accounts you own or have explicit permission to test.
- Stop and report as soon as you have confirmed a vulnerability — a single proof-of-concept is enough.
Please do not:
- Access, modify, or delete data that is not yours, or degrade the service (no denial-of-service, spam, or automated scanning that harms availability).
- Use social engineering, phishing, or physical attacks against our team or infrastructure.
- Publicly disclose the issue, or exfiltrate any data, before we have had a chance to remediate.
How we protect your data
Traffic is served over HTTPS with HSTS, a strict Content-Security-Policy, and other hardening headers. Administrative areas sit behind Cloudflare Access. We do not run advertising or third-party tracking pixels, and we never sell your data. Payments are handled by Stripe and accounts by Google/Firebase — we never store card numbers or passwords ourselves — and IP addresses are hashed before storage. Public forms are protected by Cloudflare Turnstile. For the full picture, see our Privacy Policy.
security.txt
Our machine-readable contact details follow the RFC 9116 standard and are published at /.well-known/security.txt.