marco@luyckx.dev:~$ cat security-policy
Security policy.
Vulnerability disclosure policy for luyckx.dev, marco.luyckx.dev and blog.luyckx.dev.
Reporting
Email contact@luyckx.dev with a description of the issue, the affected URL or component, and the steps needed to reproduce it. Please allow up to 5 working days for an initial response.
Scope
In scope: luyckx.dev, marco.luyckx.dev, blog.luyckx.dev, and their published content and configuration.
Out of scope: third-party services linked from these sites (GitHub, LinkedIn, CTF platforms), the email provider's own infrastructure, and any domain not listed above.
Testing rules
Please keep testing non-destructive. Do not run denial-of-service or load testing, do not attempt to access or modify data belonging to anyone else, do not use automated scanners at a rate that degrades availability, and do not perform social engineering or physical attacks. Stop at the point where you have demonstrated the issue, and do not pivot further.
Disclosure
Please give a reasonable window to remediate before publishing. 90 days is the default expectation; shorter is fine by agreement if a fix ships sooner. Credit is offered for any valid report unless you prefer to stay anonymous.
No bounty
These are personal sites and there is no paid bug bounty. Reports are still genuinely welcome and will be acted on.