GoreeCloud

Security

Responsible security reporting

I welcome good-faith reports about security vulnerabilities affecting public-facing GoreeCloud web properties and publicly available GoreeCloud software. The goal is to make it easy to report a real security issue without exposing private systems or data.

Report securely

Email the public security contact.

Send a concise report to goreecloud@gmail.com. The machine-readable security contact is also published at /.well-known/security.txt.

What to include

A useful report should contain enough detail to understand and reproduce the issue safely.

  • The affected public GoreeCloud URL, repository, application, or version.
  • A clear description of the vulnerability and its potential security impact.
  • Minimal, reproducible steps that demonstrate the issue without causing unnecessary harm.
  • Relevant request, response, log, screenshot, or proof-of-concept details with sensitive data removed.
  • Any practical remediation idea or mitigating condition you have already identified.

Testing boundaries

This policy does not authorize testing of private family infrastructure, private services, accounts, devices, internal networks, administrative interfaces, credentials, or data that is not explicitly public. A public security policy is not permission to cross an access-control boundary.

  • Do not access, retain, modify, or disclose data that does not belong to you.
  • Do not perform destructive testing, denial-of-service activity, social engineering, credential attacks, or service disruption.
  • Do not use high-volume automated testing that could materially degrade a GoreeCloud service.
  • Do not publicly disclose exploit details before there has been a reasonable opportunity to understand and remediate the report.

How reports are handled

I will review credible reports and prioritize remediation according to likely impact, exploitability, exposure, and the safety of affected users or data. I may request additional technical detail when it is needed to reproduce or understand the issue.

GoreeCloud does not currently offer a bug bounty or guaranteed response timeline. This page provides responsible-reporting guidance and does not create authorization to access systems, accounts, or data.