// responsible disclosure

Responsible Disclosure

How to report a security issue in this site.

If you have found a security issue on this site, thank you โ€” please send a confidential, plain-text description to mailto:flagon_plazas0x@icloud.com. Reports are handled personally; there is no bug-bounty programme, no financial reward, and no public acknowledgement unless you ask for one.

What is in scope

This is a static publishing site (daily/monthly cyber-intelligence digests, a story database, a wiki and a 3D incident globe) built from public sources. Realistic in-scope findings include:

Out of scope (by design)

What we promise

OPSEC note

This site names threat actors and incident victims. A few things are fixed policy and do not constitute a vulnerability to report: incident summaries link to their public sources, only publicly-reported facts are reproduced, and PII is never unnecessarily included. Constructive review of the fact-checking pipeline is welcome at the same contact.