Report an issue

If you think you have found a security vulnerability in this website, email admin@eprojac.com with a subject line starting “Security”. Please include:

The same contact details are published in /.well-known/security.txt. We read every report, but we do not promise a response time. For questions about your personal data, use Data requests instead.

Scope

This policy covers eprojac.com and www.eprojac.com, including the feedback endpoint /api/feedback.

It does not cover:

Please send findings with a demonstrated security impact rather than raw scanner output.

Rules for good-faith research

We will not take legal action against good-faith security research on this website that follows these rules:

If you are unsure whether something is allowed, ask us first at admin@eprojac.com. We cannot give permission to test systems that belong to others, including our providers.

No bug bounty

We do not run a bug bounty programme and do not pay for reports. We are still grateful for them.

How the website is built

The website is designed to leave little room for things to go wrong. This section describes how it is built; it is not a guarantee.

We do not claim any security certification for this website. Its infrastructure runs in AWS us-east-1. Retention periods are listed in the Privacy notice.