Report a security issue
Email vulnerability reports to security@ciomon.com. Please include a clear description of the suspected issue, the affected location or service, steps to reproduce it, and any supporting evidence that can be shared safely.
Do not include sensitive personal information or data obtained from other users. If you believe sensitive material is necessary to explain the issue, first ask us how to provide it appropriately.
Responsible disclosure guidelines
- Act in good faith and avoid accessing, changing, downloading, or destroying data that does not belong to you.
- Do not disrupt services, degrade availability, use social engineering, or perform physical security testing.
- Stop testing and notify us if you encounter personal information, confidential information, or evidence of unauthorized access.
- Allow SHOMON a reasonable amount of time to investigate and address a report before any public disclosure.
- Comply with applicable law and avoid conduct that could harm SHOMON, its customers, users, or third parties.
We will review reports received through the security contact and may request additional information. No bug bounty or monetary reward is currently promised.
Security contact file
Our machine-readable security contact information is available at /.well-known/security.txt. That file is managed separately through Cloudflare.