Vulnerability disclosure
Last updated: April 2026.
Purpose
If you believe you have found a security vulnerability in this website or systems clearly operated for axg.rocks, please report it responsibly so it can be addressed before public disclosure.
Scope
This policy applies to axg.rocks and related infrastructure operated directly for this personal site. It does not authorize testing against third parties, clients, or systems you do not have permission to assess.
How to report
Email [email protected] with subject line “VDP” or “Vulnerability report.” Include a clear description, steps to reproduce, and potential impact. Please allow reasonable time for a fix before any public disclosure.
Out of scope
Social engineering, physical attacks, resource exhaustion intended to cause outage, or access to others’ data without authorization are not in scope. Comply with applicable laws at all times.