Protoworks vulnerability disclosure policy — Protoworks Defence Applies to: https://defence.protoworks.dev Report a vulnerability to security@protoworks.dev. Good-faith security research on this site is welcome. When you test: - give us a reasonable window to fix an issue before you disclose it publicly; - do not run tests that degrade the service: no denial of service, load testing, or high-volume automated scanning; - do not access, change, or keep data that is not yours, and stop and tell us if you come across any; - do not use social engineering, phishing, or physical attacks. A useful report includes the affected URL, the steps to reproduce it, and the impact you observed. Machine-readable contact details: https://defence.protoworks.dev/.well-known/security.txt