Please report potential issues privately. Do not include passwords, private keys, client data, or unnecessary personal information in the initial report.
1. Reporting
Email ssiksolutions@gmail.com with the subject “Security report.” Include the affected URL, a clear description, reproduction steps, potential impact, and the minimum evidence needed to understand the issue.
2. In scope
- Public pages and original client-side code owned and maintained by SSIK.
- Accidental exposure of SSIK-controlled information through this website.
- Security or privacy defects in SSIK's own website logic.
3. Out of scope
- GitHub, GitHub Pages, email providers, Google services, or other third-party infrastructure.
- Customer, partner, school, or unrelated systems.
- Denial-of-service activity, automated high-volume scanning, social engineering, physical testing, or spam.
- Reports based only on software-version banners, missing low-impact headers, or hypothetical issues without a practical impact.
4. Safe reporting rules
- Use only the minimum interaction needed to confirm the issue.
- Do not access, copy, change, retain, or disclose information belonging to another person.
- Stop immediately if you encounter personal, confidential, or client information.
- Do not establish persistence, disrupt service, or attempt to move beyond the affected SSIK-owned asset.
- Allow SSIK reasonable time to review the report before any public disclosure.
5. Authorization and rewards
This page is not blanket authorization to test SSIK, GitHub, third-party providers, clients, or other systems. Any testing beyond the safe reporting rules above requires prior written authorization from the system owner. This page does not create a contract, guarantee legal safe harbour, or establish a paid bug-bounty program. SSIK will evaluate good-faith reports individually and confirm receipt when possible.