// security

Security

Found a hole in this site? Tell us and we will fix it. This page says where to send it, what we do with it, and what we will not do to you for sending it.

Last updated
Scope
synapsereality.io
Machine readable
/.well-known/security.txt

01 Reporting something

Email ben@synapsereality.io. We do not publish a PGP key, so describe the problem in plain terms and leave any live credentials out of the message.

What to put in the report:

Please do not put a working exploit chain in a public place before we have fixed it. If you are not sure whether something counts, send it anyway.

02 What happens next

  1. We confirm we got it, by reply, to a human.
  2. We reproduce it and tell you whether we agree with your severity.
  3. We fix it. Anything that exposes data goes first, ahead of feature work.
  4. We tell you when it is out, and we credit you if you want the credit.

If we disagree that something is a problem, we say why. You are free to disagree back, and we would rather have the argument than go quiet.

03 Safe harbour

Report in good faith and stay inside the rules below, and we will treat your testing as authorised. We will not go to a lawyer or to your hosting provider about it, and we will not ask anyone else to.

The rules:

We cannot waive anyone else's rights. If your testing hits a third party's infrastructure, their rules apply to that, not ours.

04 Scope

In scope: synapsereality.io, including the API paths under /api/ and the forms on this site.

Out of scope:

05 What this site is made of

Saving you some time. This is a static site: the pages are HTML files built ahead of time and served from a CDN. There is no CMS, no login, no user account, no payment and no file upload on it.

The only moving part is a small API behind /api/ that takes the forms, runs the audit tool and handles email replies. That is where an interesting bug would be.

06 Rewards

We do not run a paid bug bounty. What we can offer is a fast answer, a fix you can check, and public credit if you want it.

07 The machine-readable version

/.well-known/security.txt follows RFC 9116 and points back at this page. If it has expired, this page is still the right route, and telling us the file is stale is itself a useful report.