Security

Responsible disclosure for remote-ops.org.

Security reports about this website are welcome when they are made in good faith and avoid harm to users or infrastructure.

How to report an issue

Email [email protected] with a concise description, affected URL, reproduction steps, expected impact and any relevant request or response details. Remove credentials, personal data and unrelated production information.

Good-faith testing

Do not disrupt service, degrade availability, access data that is not yours, send large volumes of traffic, perform social engineering, test third-party systems without authorization, or retain data obtained unintentionally.

Preferred scope

  • Authentication or authorization defects in website functions
  • Injection, cross-site scripting or request forgery
  • Exposure of application secrets or private form submissions
  • Security-header or origin-control issues with practical impact

Out of scope

  • Automated scanner output without a verified impact
  • Missing headers with no exploit path
  • Denial-of-service testing
  • Rate-limit testing that creates excessive traffic
  • Reports about unrelated providers or domains

Response

Reports will be reviewed based on reproducibility, severity and scope. This page does not establish a bug-bounty program or promise financial compensation.

Security.txt

A machine-readable policy is available at /.well-known/security.txt.