Skip to main content
security · responsible disclosure

$ cat /.well-known/security.txt

Security policy

This policy covers security issues affecting newnol.io.vn and repositories that I explicitly own. It does not grant authorization to test third-party systems, production services belonging to others, or assets outside a published scope.

Report a vulnerability

Send reports to tantai@newnol.io.vn. English and Vietnamese are both welcome.

Please avoid sending active credentials, complete user datasets, destructive payloads, or information collected from systems you are not authorized to test.

Useful report details

  • The affected URL, component, or repository.
  • A concise description of the security impact.
  • Reproduction steps that are safe and limited to authorized systems.
  • Relevant request/response details with secrets and personal data removed.
  • A suggested remediation or defensive observation, when available.

Safe-harbor expectations

Act in good faith and stop testing when sensitive data or service instability appears.

Use the minimum interaction necessary to demonstrate impact.

Do not publicly disclose an issue before there has been a reasonable opportunity to investigate and remediate it.

Do not use findings for extortion, unauthorized access, persistence, or disruption.

Machine-readable contact information is available at /.well-known/security.txt.