Security Reporting Policy
I take the security of this website seriously. If you believe you have found a security vulnerability affecting antfie.com, I want to hear about it, and I appreciate the time and effort of the researchers who help keep the site secure.
Reporting a vulnerability
Please report it using the contact form on this website. Include enough detail for me to reproduce and understand the issue, such as:
- the URL or page affected
- a description of the vulnerability and its potential impact
- clear, step-by-step instructions to reproduce it
- any proof-of-concept code, screenshots, or logs that help
What to expect
I will acknowledge your report as soon as I reasonably can, keep you informed as I investigate, and work to fix confirmed issues in good time based on their severity. This is a personal site maintained in my own time, so I appreciate your patience.
Guidelines
I ask that you:
- give me a reasonable opportunity to fix an issue before disclosing it publicly
- only interact with data that belongs to you, or that you have explicit permission to test
- avoid actions that could harm the site or its users, such as denial-of-service testing, spamming, or degrading performance
- do not access, modify, or delete data that is not yours, and stop and report immediately if you encounter personal data that is not your own
Safe harbour
If you make a good-faith effort to follow this policy, I will treat your research as authorised, work with you to understand and resolve the issue, and will not pursue or support legal action against you in relation to it.
Out of scope
The following are generally not considered security vulnerabilities under this policy:
- reports from automated scanners without a demonstrated, exploitable impact
- volumetric denial-of-service or resource-exhaustion attacks
- social engineering
- missing security headers or best-practice suggestions with no direct security impact
- spam, or issues that require a compromised device or physical access to exploit
Last updated: 23 July 2026.