Security
Vulnerability disclosure
Last updated 20 July 2026
We take the security of this site seriously and welcome reports from good-faith security researchers. This page explains how to report a vulnerability, what is in scope, and what you can expect from us.
Reporting a vulnerability
Email [email protected]with as much detail as you can, including:
- the affected URL or endpoint;
- the type of vulnerability and its potential impact;
- step-by-step reproduction instructions, including any request/response detail, proof-of-concept code or screenshots;
- your assessment of severity, if you have one.
Please encrypt sensitive details where practical, and avoid including any real personal data belonging to others in your report.
Scope
In scope: porqueno.studio and its subdomains.
Out of scope:
- third-party services we use but do not operate (for example our email, hosting or analytics providers);
- volumetric or denial-of-service testing;
- social engineering, phishing, or physical attacks against our staff or premises.
Safe harbour
We will not pursue legal action against good-faith research conducted within this scope and in line with this policy. Please act in good faith: do not access, modify or exfiltrate other people's data, do not degrade or disrupt the service for others, and stop testing and report to us immediately once you have established a vulnerability exists.
What to expect
We aim to acknowledge your report within 3 working days. We will keep you updated as we investigate and resolve the issue, and we are happy to credit you here once it is fixed, if you would like that.