Legal
Security policy
Last updated 29 Sep 2026
If you've found a security problem in muxover.com, one of its subdomains, or one of my open-source projects, thank you. Please report it privately so I can fix it before it's used against anyone.
How to report
Email contact@muxover.com with "Security" in the subject. Please include:
- what's affected: the address, or the project and version;
- what the problem is and what someone could do with it;
- the steps to reproduce it, and any proof of concept.
Don't open a public GitHub issue for a vulnerability. The same address is listed in security.txt.
What happens next
- I reply within 48 hours to confirm I've got it.
- I keep you updated while I look into it and fix it.
- Once it's fixed, you can publish your findings. For open-source projects, the fix ships in a new release.
- If you'd like, I'll credit you in the release notes.
There's no paid bug bounty.
In scope
- muxover.com and its subdomains.
- The open-source projects under github.com/muxover, in their latest release.
Out of scope
- Denial of service, load testing, or anything that degrades the site for others.
- Spam or automated submissions through the contact form.
- Social engineering, phishing, or physical attacks.
- Services run by others, such as Cloudflare, GitHub or Resend. Report those to them.
- Reports from automated scanners without a demonstrated impact.
Good-faith research
If you act in good faith, stay within this policy, don't access or change other people's data, and give me a reasonable time to fix the problem before telling anyone, I won't take legal action against you for your research.