Skip to main content
Security Protocol

Responsible disclosure guidelines for reporting security vulnerabilities.

Report a Vulnerability

Found a security issue? Contact me directly at [email protected]

SEND_REPORT

01. Scope

This security policy applies to the following assets:

  • raoufabedini.dev This portfolio website
  • Any open-source repositories under github.com/Raoof128

02. What to Report

In Scope

  • Cross-Site Scripting (XSS)
  • Cross-Site Request Forgery (CSRF)
  • Security misconfigurations
  • Information disclosure
  • Authentication/authorization flaws
  • Injection vulnerabilities

Out of Scope

  • Social engineering attacks
  • Physical security issues
  • Denial of Service (DoS/DDoS)
  • Spam or phishing attempts
  • Issues in third-party services
  • Rate limiting issues

03. Response Timeline

Initial Response: 48-72 hours

I will acknowledge receipt of your report and provide an initial assessment.

Resolution: 7-30 days

Depending on severity, I will work to resolve the issue within this timeframe.

Disclosure: Coordinated

We will coordinate public disclosure after the fix is deployed.

04. Responsible Disclosure Guidelines

  • 1.Do not access, modify, or delete data that does not belong to you.
  • 2.Do not perform attacks that could harm the availability of services.
  • 3.Provide sufficient information to reproduce the vulnerability.
  • 4.Give reasonable time to address the issue before public disclosure.
  • 5.Act in good faith and avoid privacy violations.

05. Acknowledgments

I appreciate responsible security researchers who help improve the security of my projects. Valid reports may be acknowledged in the Security Hall of Fame.

Note: This is a personal portfolio project. No monetary bounties are offered, but your contribution will be recognized.