Security Policy
Jump to IndexTru Web Design Co Policy 5 of 5
Reporting a vulnerability
If you find a security issue in this site or the build pipeline:
Email oc.ngisedbewurt@ytiruces.
Or use the contact form on this site, located at https://truwebdesign.co/contact/.
Please do not open a public issue for security bugs.
What is in scope
The hosted site at https://truwebdesign.co and its subdomains.
What is out of scope
Reports about missing security headers without a demonstrable impact — the site’s headers are documented in public/_headers and the relevant spec pages.
Reports generated solely by automated scanners with no proof of exploit.
Social engineering attempts against maintainers.
Response
We will acknowledge a valid report within 3 business days.
We will notify you on a fix and disclosure timeline.
The disclosure window is typically 90 days from the acknowledgement, or sooner if a fix ships earlier.
Acknowledgements
Contributors who responsibly report security issues are credited in the report unless they prefer otherwise.
See also /.well-known/security.txt — the machine-readable version, per RFC 9116.