Skip to main content
On this page

Last Updated: July 24, 2026

This is the policy referenced by security.txt per RFC 9116. It is published here, on the public site, so that you do not need any account or access to read it before reporting.

Reporting a Vulnerability

If you discover a security vulnerability in Nine Lives, Zero Trust, please report it responsibly.

What to include

  • Description of the vulnerability
  • Steps to reproduce
  • Potential impact
  • Suggested fix, if you have one

Response Timeline

StageTarget
AcknowledgmentWithin 48 hours
Initial assessmentWithin 5 business days
Resolution for critical issuesWithin 30 days

Scope

In scope:

Out of scope:

  • Third-party services (Cloudflare, GitHub, Giscus, follow.it)
  • Social engineering attacks
  • Denial of service attacks

Safe Harbor

I will not pursue legal action against researchers who:

  • Make a good faith effort to avoid privacy violations, data destruction, and service disruption
  • Only interact with accounts they own, or with explicit permission
  • Report vulnerabilities promptly and do not publicly disclose before a fix is available

Recognition

I appreciate the security community’s efforts. Reporters of valid vulnerabilities will be credited, with permission, in the security acknowledgments.

Security Measures

This site implements:

  • Content Security Policy with script hash validation
  • Subresource Integrity on all JavaScript
  • HTTP Strict Transport Security with preload
  • Enforced CSP reporting via /csp-report. Trusted Types reporting remains disabled until the remaining intentional DOM HTML sinks are migrated
  • Rate limiting on API endpoints
  • CORS origin allowlist, no wildcards
  • HttpOnly, Secure, and SameSite cookies for OAuth
  • Input sanitization on all dynamic content

Machine-Readable Contact

security.txt carries the same contact information in RFC 9116 format.