How to report
Email [email protected] with the subject “Security report”. Include what you found, where, how to reproduce it, and its impact. The same contact is published in security.txt.
I acknowledge reports within 3 US business days, keep you updated, and tell you when it’s fixed. With your agreement, I’ll credit you once it’s fixed. There’s no paid bug bounty.
In scope
- morsalin.online, including the client portal, admin sign-in and public APIs.
Out of scope: my clients’ systems (report those to the client), third-party services I use (report those to them), and findings with no real security impact, such as missing headers without an exploit, or rate limits.
Rules for good-faith research
- Only test with accounts you control, and don’t access, change or keep other people’s data. If you reach any by accident, stop, tell me, and delete what you have.
- No denial-of-service, spam, social engineering, physical attacks or automated scanning that loads the site heavily.
- Give me reasonable time to fix the problem before telling anyone else. 90 days is normal, or sooner once it’s fixed.
If you follow these rules, I consider your research authorized, won’t take legal action over it, and will support you if anyone else does.