Part of the DJames Network / HDJames
Explore the Network
HDJames Application Lab

DJames Network trust

Responsible Vulnerability Disclosure

How to report a security vulnerability affecting DJames Network sites or applications.

Scope

Reports about authentication bypass, authorization defects, exposed data, injection flaws, unsafe redirects, vulnerable dependencies, or sensitive information disclosure are in scope.

Safe testing

Use non-destructive testing. Do not access other users data, run denial-of-service tests, exfiltrate data, alter production records, or publish details before coordination.

What to include

Include the affected URL or application, concise reproduction steps, expected and actual behavior, impact, screenshots if useful, and your preferred contact method. Do not include secrets in the report.

No bounty program

There is no paid bug-bounty program at this time. Good-faith reports are appreciated and will be reviewed as promptly as practical for a personally operated network.