TOSWO

Security

How to report a vulnerability in TOSWO, and what you can expect from us.

Report a security problem

If you found a vulnerability in this site, thank you. Please write to [email protected] with the subject "Security", and tell us:

  • what you found and where,
  • the steps to reproduce it,
  • what you think the impact is.

What we ask

  • Give us reasonable time to fix it before you publish.
  • Do not read, change or delete data that is not yours, do not degrade the service, and stop at proof of the problem.
  • Do not test with social engineering or physical access.

What you can expect

We will confirm we received your message, keep you informed, fix real problems quickly and, if you wish, credit you when we publish the fix. We will not take legal action against good-faith research that follows these rules.

Not in scope

Missing best-practice headers with no demonstrated impact, results of automated scanners without a proof of concept, and the behavior of the AI providers we monitor (for that, see our disclosure policy).

A machine-readable version of this page is at /.well-known/security.txt.