Last updated: 5 September 2026
Reporting an issue
Email security@sts.zone with enough detail to reproduce it. You do not need to prove impact and you do not need a polished report. If a plain description is all you have, send that.
What we commit to
We acknowledge within one working day, tell you what we found, and tell you when it is fixed. We will not pursue anyone who reports in good faith and does not access, change or keep data belonging to other people.
What we ask
Give us a reasonable window before publishing. Do not run denial of service tests, do not use automated scanners against production, and stop as soon as you have shown a problem exists.
How we run things
This site is served over TLS with HSTS and carries a content security policy. That policy allows scripts from this site and from googletagmanager.com, and nothing else. The one exception exists so Google Analytics can load after you accept the cookie banner, and nothing is fetched from Google before you do. Every other asset - fonts, styles, icons - is served from here. Our mail is protected with SPF, DKIM, DMARC and MTA-STS in enforce mode. We patch on our own schedule and we monitor what we run.
Start with the problem.
A short conversation is usually enough to tell whether this is something we should be doing for you.