Security & Vulnerability Disclosure

Security & Vulnerability Disclosure

I value responsible reporting of security vulnerabilities affecting davydkin.com.

If you believe you have identified a security issue related to this website, please report it privately to security@davydkin.com.

Reporting a vulnerability

When possible, include:

  • the affected URL or component;

  • a clear description of the issue;

  • its potential security impact;

  • steps required to reproduce it; and

  • supporting technical details that may help validate the finding.

Please do not include sensitive personal information unless strictly necessary to explain the vulnerability.

Scope

This policy applies to davydkin.com and website functionality or configuration under the direct control of the site owner.

Third-party services, infrastructure, platforms, or systems used by the website are outside the scope of this policy unless the vulnerability results specifically from the configuration of davydkin.com.

Vulnerabilities affecting a third-party service itself should be reported directly to that provider.

Responsible testing

Please use only the minimum testing necessary to demonstrate a vulnerability.

Do not:

  • access, download, modify, or delete data belonging to other people;

  • attempt to obtain other users’ credentials;

  • perform denial-of-service or resource-exhaustion testing;

  • use automated testing that may materially degrade the website;

  • perform social engineering, phishing, or physical-security testing;

  • introduce malware or persistent access; or

  • intentionally disrupt the website or related services.

Responsible disclosure

Please allow reasonable time to investigate and, where appropriate, address a reported vulnerability before making technical details public.

Reports made in good faith and in accordance with this policy are welcomed.

Bug bounty

davydkin.com does not operate a paid bug bounty program.

Reporting a vulnerability does not create an entitlement to payment, compensation, or other reward.

Security contact

Preferred language: English

Machine-readable security information: