Draft — not yet reviewed by a lawyer.
Security and Responsible Disclosure
Last updated September 27, 2026Version 0.2
In plain language
If you find a security problem, please tell us privately and give us time to fix it. We won't take legal action against good-faith research that follows these rules.
Reporting a vulnerability
Please report security issues privately through the contact form (topic "Something else", starting with "SECURITY") or TODO: security email / security.txt. Include what you found, steps to reproduce and the impact you expect.
Our commitment
- We will acknowledge your report within TODO: number working days.
- We will keep you updated while we investigate and fix it.
- We will credit you, if you wish, once it is fixed.
- We will not take legal action against research done in good faith that follows these rules.
Please
- Test only your own accounts and data.
- Don't access, change or delete other people's data, including recitation results.
- Don't run denial-of-service tests, spam, social engineering or physical attacks.
- Give us reasonable time to fix the issue before telling anyone else.
How we protect data
- Encrypted connections everywhere, with strict transport security.
- Row-level security in the database: each user can reach only their own rows.
- Staff tools on a separate site with two-factor sign-in, role checks and an audit log.
- A strict content security policy and other security headers.
- No storage of recitation audio, and error reports with personal data removed.