Vulnerability disclosure

If you found something, tell me.

This is the policy /.well-known/security.txt points at. It is short because the attack surface is small, and specific because “email us” is not a policy.

How to report

Email hi@andrewryan.consulting with enough detail to reproduce it — a URL, the request, and what you expected instead. If you would rather not send the detail in plaintext, say so in a one-line email and I will arrange an encrypted channel before you send anything sensitive.

What I commit to

What I cannot offer is money. There is no bug bounty, and I am not going to pretend otherwise to look bigger than I am.

Scope

In scope: andrewryan.consulting and its subdomains, the seven dashboard demos including the file reader they carry, the published security kit, and the response headers.

Out of scope, because they are not mine to fix and reporting them to me wastes your time:

Rules

Acknowledgements

Nobody yet. If that changes, names go here — with permission.

Version 1.0 · last reviewed 18 August 2026.

Not a security report?

The security & deployment page answers the questions a reviewer usually has. This page is only for reporting a defect in the site itself.

Email me