In scope
- Website content and configuration on molansen.com and its subdomains.
- Applications released by MOLANSEN, including their update and distribution paths.
- Security defects in source repositories that we make public.
If you find a security issue affecting the MOLANSEN website or a released product, please tell us directly. This page explains the scope, reporting route and response process.
Send the report by email. The following details help us understand and reproduce the issue.
contact [at] molansen.com(replace [at] with @)We do not currently publish a PGP key. For particularly sensitive reports, send an initial email without the details so we can agree on the next step.
We are a very small team without a round-the-clock security operation, and we do not run a bug-bounty programme. Genuine reports are reviewed and receive a response.
If a released product has a dedicated security contact, its product page will say so.
We do not intend to pursue legal action solely because of research that follows these guidelines, and we welcome coordinated disclosure after a fix is available.
This statement describes our position only. It cannot waive the rights of third parties or override legal obligations.
Machine-readable contact information is published at /.well-known/security.txt in accordance with RFC 9116. The file includes the contact route, expiry date and this page.