Legal

Security

Last updated: [DATE] · Bonk Bytes, [LEGAL ENTITY NAME]

How the tools are built

Every tool on this site runs client side. There is no API behind them, no request is made when you use them, and nothing you enter is stored. You can confirm this by opening your browser's network tab, or by reading app.js — it is not minified.

Reporting a vulnerability

If you find a security issue in this site or in something we built for a client, email [SECURITY CONTACT EMAIL]. Tell us what you found and how to reproduce it. We will acknowledge within [N] business days and keep you updated until it is resolved.

Please give us a reasonable window to fix an issue before disclosing it publicly. We will not pursue legal action against anyone acting in good faith under this policy.

This page is the disclosure policy referenced by our security.txt, served at /.well-known/security.txt.

CONFIRM: the acknowledgement window above, whether you run a bounty, and the contact address and Expires date in /.well-known/security.txt.

In scope

  • This website and the tools published on it.
  • Infrastructure we operate directly.

Out of scope: findings against a client's own systems. Report those to the client; we will help coordinate if you ask.

How we work on client systems

We deploy into your cloud account rather than ours, use credentials you issue and can revoke, and hand over infrastructure as code so nothing about the deployment is opaque to your team.

CONFIRM: access controls, whether staff use managed devices, MFA policy, background checks, and any certifications you actually hold. Do not claim a certification you have not been audited for.

Contact

[SECURITY CONTACT EMAIL]