Reporting
Good-faith security concerns may be sent to security@mrblindbandit.net. Include the affected URL or feature, a concise explanation, reproduction steps that avoid harm, and contact information if a response is desired.
Safe research expectations
Do not access another person's account or private data, persist in a system after demonstrating a flaw, download unnecessary records, destroy or alter data, deploy malware, conduct denial-of-service activity, use social engineering, compromise third parties, or publicly expose a vulnerability before the operator has a reasonable opportunity to investigate and mitigate it.
Good-faith handling
The operator should treat non-destructive research intended to improve security as a security report rather than automatically as abuse. Nothing in this policy authorizes conduct prohibited by law or creates immunity that the operator cannot legally grant.
Sensitive reports
Do not send passwords, full authentication tokens, complete payment information, or copied private user records unless absolutely necessary to explain the issue. Redact proof wherever possible.
Response process
Reports should be logged, triaged by severity, acknowledged when contact details are available, assigned an owner, remediated or mitigated proportionately, tested, and closed with a record of the outcome. A qualifying personal-data incident should be escalated into the privacy breach process.
Professional review notice
These public documents explain current website practices and user expectations. They are not a substitute for advice from a lawyer or regulator about a particular person, contract, jurisdiction, or dispute. Applicable rights that cannot lawfully be waived remain available.
