APSLHome →

Responsible disclosure

Security

APSL takes the security of its systems seriously. If you believe you have found a vulnerability in an APSL-operated service, please report it privately so we can investigate.

Report a vulnerability

Include the affected service, potential impact, reproduction steps, and supporting evidence.

security@apsl.dev →

What to include

  • The affected URL, component, or service
  • A clear description of the issue and impact
  • Steps needed to reproduce the behavior
  • Logs, screenshots, or proof-of-concept material where useful

Research guidelines

  • Avoid accessing, changing, or deleting other people's data
  • Do not degrade services or perform denial-of-service testing
  • Do not use social engineering, phishing, or physical attacks
  • Stop testing and contact us if sensitive data is exposed

Scope

This policy covers public internet-facing services operated by APSL. Client systems, third-party services, and infrastructure not controlled by APSL are outside its scope.

What happens next

We will acknowledge the report, investigate its validity and impact, and coordinate remediation and disclosure where appropriate. Please keep the details confidential while the issue is being addressed.

No bug bounty

APSL does not currently operate a paid bug-bounty program. Submission of a report does not create an entitlement to payment or compensation.

Security contact

Email security@apsl.dev with the subject Security vulnerability report.