Responsible disclosure
Security Policy
Responsible disclosure of potential security issues affecting andreewelker.com.
Last updated: 19 July 2026
Report a security issue
Potential vulnerabilities may be reported confidentially to [email protected]. Please include the affected URL, reproducible steps, potential impact and—where safe—a minimal proof.
Safe testing
- Do not access, modify, retain or disclose another person’s data.
- Do not perform denial-of-service activity, automated mass scanning, social engineering or spam attempts.
- Collect only the minimum proof required and stop testing after confirming the issue.
- Allow reasonable time for validation and remediation before disclosure.
Response
Reports will be acknowledged where possible, prioritised and addressed within a reasonable period. This policy does not create a bug-bounty programme or promise compensation.