Security Policy (RFC 9116)

Adopted Standards

LayerImplementation
SystemOpenBSD 7.8
Web Serverhttpd(8) with chroot
Firewallpf(4) with restrictive rules
TLSVersion 1.3 mandatory
HSTSMax-age 31536000, includeSubDomains, preload

Vulnerability Reporting

If you identify a security vulnerability:

  1. Do not test further beyond initial discovery
  2. Document steps to reproduce
  3. Send PGP-encrypted report to: security@tizianogasparet.com
  4. Await confirmation within 72 hours

Rewards

I do not offer monetary bounties. I offer:

  • Public recognition (if desired)
  • Early access to fixes
  • Permanent operational gratitude

Tiziano Gasparet — January 2026