$ cat /.well-known/security.txt
Security policy
This policy covers security issues affecting newnol.io.vn and repositories that I explicitly own. It does not grant authorization to test third-party systems, production services belonging to others, or assets outside a published scope.
Report a vulnerability
Send reports to tantai@newnol.io.vn. English and Vietnamese are both welcome.
Please avoid sending active credentials, complete user datasets, destructive payloads, or information collected from systems you are not authorized to test.
Useful report details
- The affected URL, component, or repository.
- A concise description of the security impact.
- Reproduction steps that are safe and limited to authorized systems.
- Relevant request/response details with secrets and personal data removed.
- A suggested remediation or defensive observation, when available.
Safe-harbor expectations
Act in good faith and stop testing when sensitive data or service instability appears.
Use the minimum interaction necessary to demonstrate impact.
Do not publicly disclose an issue before there has been a reasonable opportunity to investigate and remediate it.
Do not use findings for extortion, unauthorized access, persistence, or disruption.