Security
How to report a security issue to us, and how this website is protected.
1. Report a vulnerability
If you think you have found a security issue in this website or in our product, email hello@supermerco.com with “Security” in the subject. Please include what you found, how to reproduce it, and what an attacker could do with it.
We will acknowledge your report, keep you updated while we work on it, and credit you if you would like. We do not run a paid bug bounty at the moment. Our contact details are also published at /.well-known/security.txt.
2. Please stay within these rules
- Test only against your own accounts and data. Do not access, change or delete other people’s data.
- Do not run denial-of-service tests, spam our forms, or use social engineering or physical attacks.
- Give us reasonable time to fix an issue before you tell anyone else about it.
3. Good-faith research
If you follow these rules and act in good faith, we will not take legal action against you for your research.
4. How this website is protected
- HTTPS everywhere, with HSTS and a strict Content Security Policy.
- No third-party scripts, trackers or fonts.
- Rate limits and a bot trap on every form, and a size cap on every request.
- IP addresses stored only as salted hashes.
- An admin area protected by a scrypt-hashed password, login rate limits, HttpOnly SameSite=Strict session cookies and same-origin checks on every change.
5. The product
The engine runs from the command line, makes no network calls while running (except when you ask it to send fixtures to an address you give), and has one runtime dependency. See Trust for the engineering evidence.