Cerin Amroth · Disclosure Policy
security.txt
Vulnerability Disclosure Policy
We conduct good-faith security research and coordinated vulnerability disclosure.
We do not extort, sell access, retain sensitive data beyond what is necessary to demonstrate impact, deploy persistence, or disclose unresolved vulnerabilities before a reasonable remediation window has passed.
Reporting
Report a vulnerability to security@cerinamroth.com. Contact details, our encryption key, and this policy are published in security.txt. Encrypt sensitive reports to our PGP key.