Techlore Security Policy


How to report

Use our contact page.

Please include:

  • What you found, and where (a URL is ideal)
  • The steps to reproduce it
  • What an attacker could actually do with it

What to expect

  • We'll acknowledge your report as soon as we're able
  • We're a small team, so fixes are prioritized by real-world impact
  • If you'd like credit, say so and we'll add you to this page
  • We don't run a bug bounty program and don't offer payment. We're a small org

Scope

In scope: techlore.tech, tools.techlore.tech, quiz.techlore.tech,
vpn.techlore.tech, and the code behind them.

Out of scope: third-party services we merely use (our host, our email
provider, our video platforms), our social media accounts, and anything you
found on a site that isn't ours.

What we won't act on

We get a lot of automated output. To be clear about what isn't useful:

  • Raw scanner or tool output with no demonstrated impact
  • Missing security headers, TLS configuration opinions, or version disclosure,
    absent a working exploit
  • Denial of service, brute force, or anything requiring large volumes of traffic
  • Social engineering of our team or community
  • Reports about a third party's infrastructure
  • "I found a vulnerability, pay me first" emails with no details

Testing safely

Please don't access, modify, or delete data that isn't yours, degrade the
service for other people, or use automated scanning that generates significant
traffic. Test against your own accounts and data.