Reporting
If you believe you have found a security vulnerability in a Stoa system, email [email protected]. Include a technical description, the affected URL or endpoint, steps to reproduce, and any proof of concept.
Ground rules
- Act in good faith. Do not access, modify, or destroy data that does not belong to you.
- Do not degrade service availability, and do not run high-volume automated scanning against production systems.
- Do not use social engineering, phishing, or physical attacks against Stoa personnel or venue participants.
- Allow a reasonable remediation period before any public disclosure.
What to expect
We review every report. Stoa does not offer monetary rewards for vulnerability reports.
The machine-readable version of this policy is published at /.well-known/security.txt.
