▸ IN SCOPE
andri.is and all *.andri.is subdomains
Any public repo under github.com/AndriGitDev
Apps I actively run (ask if unsure)
▸ OUT OF SCOPE
— Third-party SaaS I happen to use
— Social engineering, physical attacks
— DoS / volumetric testing
— Automated scanner output without PoC (exception: Aftra tooling)
▸ RESPONSE SLA
Ongoing
Triage, severity, and periodic status updates
90 days
Reasonable time before public disclosure
On fix
Credit in the Hall of Fame (if you want it)
▸ REPORT A VULNERABILITY
Private, fast, and credited — send details and I'll acknowledge within 72 hours.
security@andri.is →PGP key available on request · /.well-known/security.txt