Security Policy
How to report a vulnerability, and what happens after you do
On this page
Last Updated: July 24, 2026
This is the policy referenced by security.txt per RFC 9116. It is published here, on the public site, so that you do not need any account or access to read it before reporting.
Reporting a Vulnerability
If you discover a security vulnerability in Nine Lives, Zero Trust, please report it responsibly.
- Email: [email protected]
- LinkedIn: Jerrad Dahlager
What to include
- Description of the vulnerability
- Steps to reproduce
- Potential impact
- Suggested fix, if you have one
Response Timeline
| Stage | Target |
|---|---|
| Acknowledgment | Within 48 hours |
| Initial assessment | Within 5 business days |
| Resolution for critical issues | Within 30 days |
Scope
In scope:
- nineliveszerotrust.com, the main site
- api.nineliveszerotrust.com, the threat feeds API
- The site’s source repository and its code
Out of scope:
- Third-party services (Cloudflare, GitHub, Giscus, follow.it)
- Social engineering attacks
- Denial of service attacks
Safe Harbor
I will not pursue legal action against researchers who:
- Make a good faith effort to avoid privacy violations, data destruction, and service disruption
- Only interact with accounts they own, or with explicit permission
- Report vulnerabilities promptly and do not publicly disclose before a fix is available
Recognition
I appreciate the security community’s efforts. Reporters of valid vulnerabilities will be credited, with permission, in the security acknowledgments.
Security Measures
This site implements:
- Content Security Policy with script hash validation
- Subresource Integrity on all JavaScript
- HTTP Strict Transport Security with preload
- Enforced CSP reporting via
/csp-report. Trusted Types reporting remains disabled until the remaining intentional DOM HTML sinks are migrated - Rate limiting on API endpoints
- CORS origin allowlist, no wildcards
- HttpOnly, Secure, and SameSite cookies for OAuth
- Input sanitization on all dynamic content
Machine-Readable Contact
security.txt carries the same contact information in RFC 9116 format.
