How to report
Email hi@andrewryan.consulting with enough detail to reproduce it — a URL, the request, and what you expected instead. If you would rather not send the detail in plaintext, say so in a one-line email and I will arrange an encrypted channel before you send anything sensitive.
What I commit to
- An acknowledgement within three working days. From one person, in one timezone, who is sometimes on a client site — so three, not one.
- An assessment within ten working days, saying whether I agree it is a vulnerability, and if so what I intend to do and roughly when.
- Credit, if you want it, on this page. Or no mention at all, if you prefer that.
- No legal action for good-faith research that stays inside the scope below. I will not threaten you for telling me something I would rather know.
What I cannot offer is money. There is no bug bounty, and I am not going to pretend otherwise to look bigger than I am.
Scope
In scope: andrewryan.consulting and its subdomains, the seven
dashboard demos including the file reader they carry, the published security kit, and the
response headers.
Out of scope, because they are not mine to fix and reporting them to me wastes your time:
- Anything hosted by Vercel below my configuration — their edge, their TLS termination, their platform. Report those to Vercel.
- Calendly, which handles booking, and Google Workspace, which handles mail.
- Findings that are the documented design rather than a defect: the site sets no cookies and has no login, so “no session cookie flags” and “no account lockout” are not findings.
- Missing headers that a scanner reports as best practice where the reason for their absence is stated on the security page — though if you think the reasoning is wrong, that is worth an email.
- Reports generated by an automated scanner with no evidence of exploitability attached.
Rules
- Do not run denial-of-service or volumetric testing against the site.
- Do not access, modify or retain data that is not yours. There is very little here to access — the site holds no accounts and no client data — but the rule stands.
- Give me a reasonable chance to fix it before publishing. Ninety days is the norm and I will not argue about it; if it is fixed sooner, publish sooner.
- Automated scanning is fine at a polite rate.
Acknowledgements
Nobody yet. If that changes, names go here — with permission.
Version 1.0 · last reviewed 18 August 2026.
Not a security report?
The security & deployment page answers the questions a reviewer usually has. This page is only for reporting a defect in the site itself.