Security

Report quietly.
Fix responsibly.

A lightweight vulnerability-reporting policy for the project’s public web properties.

Independent & non-commercialOne-person projectLast reviewed: 1 September 2026

Responsible reports are welcome.

The project is intentionally low-complexity, but low complexity is not the same as zero security risk. If you find a genuine vulnerability in a project web property, please report it privately.

Scope and boundaries

Good-faith testing should be limited to the public web applications that are clearly part of Sweden, clearly.

  • Do not perform denial-of-service or high-volume automated testing.
  • Do not access, modify or retain data that is not yours.
  • Do not use social engineering, phishing or physical attacks.
  • Do not test unrelated mail services, hosting-provider infrastructure or third-party services merely because they share infrastructure or DNS.
  • Stop when you have enough evidence to explain the problem.

No bug bounty: this is a non-commercial one-person project. There is no reward programme and no guaranteed response time.

What to include

  • affected hostname and URL;
  • clear reproduction steps;
  • impact in plain language;
  • minimal proof of concept;
  • your preferred contact method, if you want a reply.

security.txt

The project publishes /.well-known/security.txt following RFC 9116 ↗. Because a security.txt file is scoped to the hostname from which it is retrieved, serving the shared file on each project vhost provides a contact point on each hostname.

The file’s expiry date needs occasional maintenance; RFC 9116 recommends an expiry less than a year into the future.