Security Policy
Last updated:
We welcome reports of security problems affecting llcbystate.com. This page explains how to report one and what to expect.
About this site
llcbystate.com is a static publication served over HTTPS from Cloudflare's network. It has no user accounts, no comments, and no database of personal data, and its only form is a contact form that emails your message to us and stores nothing, which keeps the attack surface small. Issues most likely to matter are content-injection or script problems, misconfigured security headers, exposed files, or a compromised third-party script.
How to report
Use our contact form, choose the Security topic, and send a description of the issue, the affected URL, and steps to reproduce it. Screenshots or proof-of-concept details help. Please do not include personal data belonging to other people.
What we ask
- Give us reasonable time to investigate and fix the issue before you disclose it publicly.
- Do not access, change, or delete data that is not yours, and do not disrupt the service.
- Do not run automated scanning at a volume that degrades the site for others.
What you can expect
- An acknowledgement of your report, normally within a few business days.
- An assessment and, where the report is valid, a fix and a note back to you.
- Credit for the finding if you would like it, once the issue is resolved.
Good-faith research
We will not pursue action against researchers who act in good faith, follow this policy, and avoid harm to users or the service. We do not currently offer monetary rewards.
Our machine-readable contact details are in security.txt.