Security · responsible disclosure

Find a hole? Tell me first.

seanmaraj.com is a static marketing site with one server-side endpoint (contact intake). The attack surface is small but not zero. If you find something, this page tells you how to report it.

How to report

Email [email protected] with a description, repro steps, and (if relevant) a proof-of-concept. PGP optional. Replies within 48 hours.

Machine-readable contact: /.well-known/security.txt (RFC 9116).

What's in scope

What's out of scope

Good faith

You will not face legal action for testing performed in good faith against the public scope above. Don't exfiltrate data beyond what proves the issue, don't pivot into third-party services, and don't generate sustained load.

Hall of fame

Researchers who responsibly disclose will be acknowledged here, with their permission.