Security
Found something?
Tell us. We'll fix it.
No lawyers, no drama, no waiting weeks for a reply. Report a security issue and a senior engineer looks at it. That's the whole policy.
How to report
[email protected] — PGP-encrypted reports preferred. Encrypt with the public key.
Machine-readable
Full policy in security.txt (/security.txt) — standard fields, machine-parseable, verified on every domain we operate.
Acknowledgements
We'll credit anyone who reports a genuine vulnerability and helps us fix it, in the report and here. No swag bribery, just the respect of having found something real and having it handled properly.
No public disclosures yet. Be the first.
Hiring
We're a small senior team and we stay that way on purpose. If you're a senior operator with 10+ years in the field — SEO, engineering, security — who wants to do the work instead of the meetings, email [email protected]. No recruiters, no account managers, no HR pipeline. Just a conversation.