Security Policy
Reporting a Vulnerability
We take the security of this website seriously. Please report vulnerabilities by email, not through public channels. Do not post security issues on GitHub or similar platforms.
Send reports to [email protected]. See What to Expect below for our response timeline.
Please include as much of the following as you can:
- Issue classification (XSS, injection, misconfiguration, etc.)
- Affected URLs or source file paths
- Code location details (tag/branch/commit or URL) where applicable
- Reproduction requirements and step-by-step instructions
- Proof-of-concept or exploit code, when applicable
- A description of the exploitation impact
Encryption
For sensitive communications, PGP encryption is supported:
- Email: [email protected]
- Key type: RSA, 4096-bit
- Fingerprint:
56E2 5925 6A24 3A0E 042F 642B 4A11 0992 1303 6584 - Public key: jokinglybad.tech/pgp-key.txt
A security.txt file is maintained at jokinglybad.tech/.well-known/security.txt per RFC 9116.
Scope
This policy covers jokinglybad.tech, associated subdomains, and all related APIs and services.
What to Expect
- Acknowledgment of your report within 24 hours
- Initial assessment within 48 hours, including a projected timeline for a fix
Recognition
First reporters of unique vulnerabilities that lead to a code or configuration change receive public acknowledgment (with permission).
Legal
Good-faith disclosure that follows these guidelines will not result in legal or administrative action.
Updates to This Policy
The latest version of this policy lives at jokinglybad.tech/security-policy.