How to report an issue

Send the report by email. The following details help us understand and reproduce the issue.

contact [at] molansen.com(replace [at] with @)
  • The affected address, product name and version.
  • Reproduction steps and any relevant request and response data.
  • The impact you believe the issue may have.
  • Screenshots, logs or proof-of-concept code, where useful.

We do not currently publish a PGP key. For particularly sensitive reports, send an initial email without the details so we can agree on the next step.

What happens next

  1. We acknowledge the report and confirm our initial understanding.
  2. We assess scope and severity, and may ask for clarification.
  3. We develop and release a fix, then update the reporter.
  4. If users are affected, we publish the information needed through release notes or this website.

We are a very small team without a round-the-clock security operation, and we do not run a bug-bounty programme. Genuine reports are reviewed and receive a response.

Scope

If a released product has a dedicated security contact, its product page will say so.

In scope

  • Website content and configuration on molansen.com and its subdomains.
  • Applications released by MOLANSEN, including their update and distribution paths.
  • Security defects in source repositories that we make public.

Out of scope

  • Issues in third-party services such as an app store, hosting provider or email provider; report those to the relevant operator.
  • Automated scanner output that identifies a missing hardening measure without showing a practical impact.
  • Issues that require the user’s device to have already been fully compromised.

Good-faith security research

We do not intend to pursue legal action solely because of research that follows these guidelines, and we welcome coordinated disclosure after a fix is available.

This statement describes our position only. It cannot waive the rights of third parties or override legal obligations.

  • Do not degrade availability or perform load, stress or denial-of-service testing.
  • Do not access, alter or retain data that is not yours. If you encounter it unexpectedly, stop and notify us.
  • Do not use social engineering, phishing or physical intrusion against our staff or any third party.
  • Allow a reasonable opportunity to fix the issue before publishing directly exploitable details.
  • Comply with the laws that apply to you and to the research.

security.txt

Machine-readable contact information is published at /.well-known/security.txt in accordance with RFC 9116. The file includes the contact route, expiry date and this page.