SECURITY

Security reporting policy

Report a concern

Report suspected vulnerabilities affecting haddin.ca or www.haddin.ca through the contact page. Include the affected URL, a description, potential impact, and minimal reproduction details. Use my published public key for sensitive reports. Do not send passwords, private keys, or unnecessary personal information.

Reporting is not testing authorization

This policy welcomes reports of issues you encounter. It does not authorize penetration testing, exploitation, automated scanning, social engineering, denial-of-service testing, or attempts to bypass access controls. Obtain explicit written authorization before conducting security testing.

Employers and third parties are excluded

This is a personal website. I do not grant authorization on behalf of any current or former employer, client, service provider, or other third party. Do not use me, my identity, accounts, devices, domains, or hosted systems as a foothold, relay, pretext, or route to investigate or attack another organization. Direct employer-related reports and authorization requests to that organization鈥檚 own security team and disclosure process. Employment, links, and references do not imply permission or endorsement.

Minimize harm

If you encounter sensitive data or unintended access, stop immediately and report it privately. Do not access additional records, alter data, establish persistence, or move into other systems. Coordinate disclosure to allow reasonable time for assessment and remediation.

Expectations

This is not a bug-bounty program. No payment, response deadline, testing authorization, or legal safe harbour is promised. Acknowledging a report does not authorize further activity.

Contact & securitysecurity.txt