00 / Responsible disclosure

Found a hole in Deckproof? Tell us and we will fix it.

We check other people’s sites for a living, so ours had better hold up. If you find a security problem in Deckproof, we want to hear about it, and you will not get a lawyer’s letter for looking.

How to report

Write to jonasklein.business@pm.me with the word SECURITY in the subject. Tell us what you found, how to reproduce it, and what an attacker could do with it. A short mail is fine; a proof of concept is better.

We answer within 72 hours, tell you what we intend to do, and let you know when it is fixed. If you want credit on this page, say so and we will add you.

What is in scope

deckproof.dev and everything under it, including the scan API, the report pages, the unlock flow and the emails we send.

What is out of scope

Reports from automated scanners with no working exploit. Missing headers on pages that carry nothing. Rate-limit findings that need thousands of requests. Anything on a site we scanned rather than on Deckproof itself: those belong to their owners, not to us. Our payment pages are run by Paddle; report those to Paddle.

What we ask of you

Stay within your own data. Do not read, change or delete anyone else’s. Do not run denial-of-service tests. Do not publish the problem until we have shipped a fix, or 90 days have passed, whichever comes first. If you stay inside those lines, we will not pursue you, and we will not report you.

Reward

We are one person and a small product, so there is no bug bounty. What we can give you is a fast answer, a fix, public credit if you want it, and a free Agency plan for a year for anything genuinely serious.

Machine-readable

The same policy in the RFC 9116 format: /.well-known/security.txt.