Security Policy

Vulnerability Disclosure Policy for amroot.com

Reporting a Vulnerability

Report suspected security issues to [email protected]. Reports are accepted in English. This policy is also published in machine-readable form at /.well-known/security.txt.

What To Expect

amroot.com is a personal site maintained outside of working hours, so the timelines below are good-faith targets rather than contractual guarantees.

Scope

In scope: the amroot.com domain and its subdomains, including the static site content, its HTTP response headers, and its DNS configuration.

Out of scope: third-party platforms linked from this site, including Medium, GitHub, and LinkedIn. Those services run their own disclosure programs and should be contacted directly. Findings that affect only a third party's infrastructure are not covered here.

The following are not accepted as vulnerabilities:

Safe Harbor

Security research conducted in good faith and in accordance with this policy is welcome, and no legal action will be pursued in response to it. To stay within this protection, please:

This safe harbor covers only claims that the site owner is entitled to bring. It cannot bind hosting providers, third-party platforms, or any other party.

Recognition and Rewards

There is no monetary bounty. amroot.com is a personal site and does not operate a paid bug bounty program. No payment will be offered or issued for any report, regardless of severity.

Valid reports are credited publicly by name or handle, with thanks, unless you prefer to remain anonymous. Just tell us which you would like when you report.