security · responsible disclosure

Report a security issue.

If you think you have found a vulnerability in anything I run, please tell me so I can fix it. Good-faith reports are welcome.

How to report

Email security@happypaul55.com with the details. To help me reproduce and fix the issue quickly, please include:

  • The affected site or service, and the URL where it occurs.
  • A description of the issue and what an attacker could do with it.
  • The steps to reproduce it, and any proof of concept.
  • Any screenshots, logs or requests that show the problem.

What to expect

  • I aim to acknowledge your report within three working days.
  • I will investigate it, keep you updated, and tell you whether I consider it a vulnerability.
  • I will let you know when a fix has shipped and, if you would like, credit you for the report.

Please do not

  • Access, change or delete data that does not belong to you.
  • Disrupt or degrade these services, or anyone else's.
  • Run automated scans that generate significant load.
  • Disclose the issue publicly before I have had a reasonable chance to fix it.

Scope

This policy covers happypaul55.com and its subdomains, together with pokerhudxl.com. It does not cover third-party products or services that I use but do not control.