Security
Reporting a vulnerability
If you have found a security issue in any Antypas Ventures system, we want to hear about it. Reports are read by the people who can fix them.
Where to send it
security@antypasventures.comInclude enough detail to reproduce the issue — affected URL or endpoint, the steps you took, and what you observed. If a proof of concept helps, attach it.
What to expect
- Acknowledgement of your report within three business days.
- An assessment and a remediation plan, or an explanation of why we disagree.
- Notification when the issue is resolved.
- Credit for the finding if you would like it, once a fix is deployed.
In scope
antypasventures.comand its subdomains.- The platforms listed on this site, at their own domains. Reports for those may also be sent here and will be routed.
Out of scope
- Findings that require physical access to a device or network.
- Social engineering of staff, customers or suppliers.
- Denial-of-service testing, or any testing that degrades a live service.
- Reports generated solely by an automated scanner with no demonstrated impact.
- Missing hardening headers or best-practice recommendations with no exploitable consequence.
Good-faith research
- We will not pursue or support legal action against anyone who reports in good faith under this policy.
- Please act only against systems in scope, use no more access than a proof of concept requires, and do not access, alter or retain anyone else's data.
- Give us a reasonable opportunity to fix the issue before disclosing it publicly.
This policy is also published in machine-readable form at /.well-known/security.txt, per RFC 9116.