Security
If you have found something, we want to hear it before anyone else does.
Last updated: 20 August 2026
Reporting an issue
Email security@sts.zone with enough detail to reproduce it. You do not need to prove impact and you do not need a polished report. If a plain description is all you have, send that.
What we commit to
We acknowledge within one working day, tell you what we found, and tell you when it is fixed. We will not pursue anyone who reports in good faith and does not access, change or keep data belonging to other people.
What we ask
Give us a reasonable window before publishing. Do not run denial of service tests, do not use automated scanners against production, and stop as soon as you have shown a problem exists.
How we run things
This site is served over TLS with HSTS, carries a content security policy that permits no third-party scripts, and self-hosts every asset. Our mail is protected with SPF, DKIM, DMARC and MTA-STS in enforce mode. We patch on our own schedule and we monitor what we run.
Start with the problem.
A short conversation is usually enough to tell whether this is something we should be doing for you.