← Back to Portfolio

Responsible Disclosure

Last Updated: August 2026

1. Security Stance

As a cybersecurity professional, I take the security of my infrastructure seriously. I value the input of independent security researchers and the broader infosec community. If you discover a vulnerability within this portfolio or its underlying infrastructure, I encourage you to report it responsibly.

2. Safe Harbor

I will not initiate legal action or file complaints against researchers who discover and report vulnerabilities in good faith, provided they adhere strictly to the guidelines outlined in this policy.

3. Reporting Guidelines

To ensure a mutually beneficial disclosure process, please adhere to the following:

  • Do Not Exploit: Do not exploit the vulnerability beyond what is strictly necessary to prove its existence. Do not exfiltrate, delete, or manipulate data.
  • No Destructive Testing: Do not perform Denial of Service (DoS/DDoS) attacks, spam the contact endpoints, or execute volumetric fuzzing that degrades site performance.
  • No Social Engineering: Do not attempt social engineering, phishing, or physical attacks against me or the hosting providers (Vercel, Supabase).
  • Provide Details: Include clear, reproducible steps, proof-of-concept code, and potential impact in your report.

4. Scope

The following targets are considered IN SCOPE:

  • The primary domain: webjothishanalyst.site
  • API routes under /api/*
  • Supabase RLS bypasses leading to unauthorized data access.

Note: Vulnerabilities in third-party services (Vercel, Supabase backend infrastructure) should be reported directly to those vendors.

5. Expected Response Timeline

I will make a best-effort attempt to triage your report within 48 hours and provide an estimated timeline for a patch. Once patched, you will be credited in the site's changelog if you desire.

6. Contact

Please email your findings securely.

Security Contact: gandhamjothish1@gmail.com