Send a private report
Use the subject line “Security report” and do not attach executable files. A dedicated security mailbox can replace this contact once it is configured.
contact@semenenko-nikoloz.devWhat to include
- The exact page or asset affected.
- What you expected and what happened instead.
- Short, non-destructive reproduction steps.
- The likely impact and any safe supporting evidence.
- A contact method for follow-up, if you want a reply.
Remove credentials, private messages, tokens, and unrelated personal information from screenshots or logs.
Testing boundaries
This page and security.txt provide a reporting route. They do not authorize testing, non-public access, disruption, social engineering, high-volume requests, or tests against third-party providers.
If ordinary browsing reveals sensitive data, stop, preserve only the minimum needed to identify the issue, and report it.
What happens next
I will identify the affected surface and assess the risk before preparing a fix. There is no public bug bounty or guaranteed response or payment schedule.
Personal data in a report is used only to investigate, respond, document the issue, and meet legal duties. See the privacy notice for contact details and rights.