I treat security as a continuous process. Systems change, software changes, and new weaknesses can appear over time.

If you discover a security issue affecting the Monolith, I would rather hear about it privately before it becomes public.

1. Reporting a Vulnerability

If you identify a security vulnerability or a configuration problem within my infrastructure:

  1. Encryption: Use my public cryptographic key when the contents of the report need to be protected.

  2. Submission: Send the report exclusively to security@tizianogasparet.com.

  3. Discretion: Please do not publicly disclose the vulnerability while I have the opportunity to investigate and mitigate it.

2. Recognition

I do not operate a commercial bug-bounty programme or offer monetary rewards.

When appropriate, I may publicly acknowledge a responsible security report, subject to the reporter’s consent.

I appreciate anyone who helps me make the Monolith more secure.

Tiziano Gasparet