DISCLOSURE POLICY

Research responsibly.
Publish deliberately.

I aim to report security vulnerabilities privately to the affected vendor or through the relevant vulnerability disclosure / bug bounty program before publishing technical details.

Publication

Write-ups are published only when disclosure is permitted or otherwise appropriate. Findings that are still under coordinated disclosure remain private and are not included in the public build of this site.

Evidence

Published research clearly distinguishes observed behavior from assumptions. Where appropriate, write-ups include reproduction details, affected versions, proof-of-concept material, and remediation context.

Safety

Research is performed in authorized environments and is intended to improve the security of affected products and users.