I treat security as a continuous process. Systems change, software changes, and new weaknesses can appear over time.
If you discover a security issue affecting the Monolith, I would rather hear about it privately before it becomes public.
1. Reporting a Vulnerability
If you identify a security vulnerability or a configuration problem within my infrastructure:
-
Encryption: Use my public cryptographic key when the contents of the report need to be protected.
-
Submission: Send the report exclusively to security@tizianogasparet.com.
-
Discretion: Please do not publicly disclose the vulnerability while I have the opportunity to investigate and mitigate it.
2. Recognition
I do not operate a commercial bug-bounty programme or offer monetary rewards.
When appropriate, I may publicly acknowledge a responsible security report, subject to the reporter’s consent.
I appreciate anyone who helps me make the Monolith more secure.
Tiziano Gasparet