Security Policy

Jump to Index

Tru Web Design Co Policy 5 of 5

Reporting a vulnerability

If you find a security issue in this site or the build pipeline:

Email oc.ngisedbewurtobfsctd-2f29ab@ytiruces.
Or use the contact form on this site, located at https://truwebdesign.co/contact/.
Please do not open a public issue for security bugs.

What is in scope

The hosted site at https://truwebdesign.co and its subdomains.

What is out of scope

Reports about missing security headers without a demonstrable impact — the site’s headers are documented in public/_headers and the relevant spec pages.
Reports generated solely by automated scanners with no proof of exploit.
Social engineering attempts against maintainers.

Response

We will acknowledge a valid report within 3 business days.
We will notify you on a fix and disclosure timeline.
The disclosure window is typically 90 days from the acknowledgement, or sooner if a fix ships earlier.

Acknowledgements

Contributors who responsibly report security issues are credited in the report unless they prefer otherwise.

See also /.well-known/security.txt — the machine-readable version, per RFC 9116.

Tru Web Design Co