// security
Security
Found a hole in this site? Tell us and we will fix it. This page says where to send it, what we do with it, and what we will not do to you for sending it.
01 Reporting something
Email ben@synapsereality.io. We do not publish a PGP key, so describe the problem in plain terms and leave any live credentials out of the message.
What to put in the report:
- The URL or endpoint, and the exact request if there is one.
- What an attacker gets out of it. That is what decides how fast we move.
- Enough steps for us to reproduce it. A short recording beats a long description.
- Whether anyone else knows, and whether you plan to write it up.
- How you want to be credited, or that you would rather not be.
Please do not put a working exploit chain in a public place before we have fixed it. If you are not sure whether something counts, send it anyway.
02 What happens next
- We confirm we got it, by reply, to a human.
- We reproduce it and tell you whether we agree with your severity.
- We fix it. Anything that exposes data goes first, ahead of feature work.
- We tell you when it is out, and we credit you if you want the credit.
If we disagree that something is a problem, we say why. You are free to disagree back, and we would rather have the argument than go quiet.
03 Safe harbour
Report in good faith and stay inside the rules below, and we will treat your testing as authorised. We will not go to a lawyer or to your hosting provider about it, and we will not ask anyone else to.
The rules:
- Stop as soon as you have proof. Do not read, copy, change or keep anyone's data.
- Use your own accounts and your own test data.
- No denial of service, no load testing, no spam through our forms.
- No social engineering of our people or our suppliers, and nothing physical.
- Stay inside the scope below.
- Give us a reasonable window to fix it before you publish.
We cannot waive anyone else's rights. If your testing hits a third party's infrastructure, their rules apply to that, not ours.
04 Scope
In scope: synapsereality.io, including the API paths under /api/ and the forms on this site.
Out of scope:
- Any host we have not listed above.
- Services run by other companies. Cloudflare, Google, Microsoft, PostHog and Resend each take reports directly, and they are the only ones who can fix their own products.
- A missing header or a weak cipher with no demonstrated impact.
- Scanner output pasted in without a reproduction.
- Volumetric attacks, rate-limit probing and anything that degrades the site for other people.
- Spam, phishing or SPF and DMARC opinions about a domain that does not send mail.
05 What this site is made of
Saving you some time. This is a static site: the pages are HTML files built ahead of time and served from a CDN. There is no CMS, no login, no user account, no payment and no file upload on it.
The only moving part is a small API behind /api/ that takes the forms, runs the audit tool and handles email replies. That is where an interesting bug would be.
06 Rewards
We do not run a paid bug bounty. What we can offer is a fast answer, a fix you can check, and public credit if you want it.
07 The machine-readable version
/.well-known/security.txt follows RFC 9116 and points back at this page. If it has expired, this page is still the right route, and telling us the file is stale is itself a useful report.