Coordinated vulnerability disclosure
Project-AI invites inspection. This page describes how to report a security issue, what is in scope, and what response you can expect.
Email founderoftp@thirstysprojects.com with reproduction steps and expected vs. observed behavior. No separate PGP or encrypted-reporting key is currently published; do not include secrets in the initial report. The portal's declared audit key is documented at /keys.
- Acknowledgement: within 72 hours.
- Triage + severity rating: within 7 days.
- Fix or mitigation plan: within 30 days for high/critical.
- Credit (if you want it) on the disclosed advisory.
- The public portal at thirstysystems.com.
- Server functions, RLS policies, auth flows, T&C gate.
- Receipt signing, chain continuity, key handling.
- Published architecture / governance documents (factual integrity).
- Volumetric DoS / DDoS, traffic floods, and automated scanning behavior.
- Social engineering of the author or third parties.
- Physical attacks against any operator.
- Self-XSS and missing security headers, including reports without demonstrated impact.
- Reports generated by automated scanners, including reports not yet manually validated.
All categories above are in scope for reporting and triage. You may submit passive observations, controlled local reproductions, and evidence already available to you. Do not generate traffic floods, run automated scans against the production service, contact or deceive people, interact with physical assets, or test third-party systems. Those actions require prior written authorization before execution.
Automated-scanner output, self-XSS, and header observations are accepted as unvalidated reports, even without demonstrated impact. They require manual validation and impact assessment before they are confirmed as findings.
Good-faith research and reporting conducted under this policy will not be pursued. Unless separately approved in writing, you must (a) avoid privacy violations, data destruction, and service degradation, (b) only interact with accounts, people, physical assets, and systems you own or are explicitly authorized to test, (c) give us reasonable time to remediate before public disclosure, and (d) not exfiltrate data beyond what is necessary to demonstrate the issue. Activities identified above as requiring prior written authorization are covered by this safe harbor only after that authorization is granted and only within its stated limits.
Machine-readable contact metadata is published at /.well-known/security.txt per RFC 9116.