Coordinated disclosure · reviewed August 21, 2026
Report risk.
Protect people.
This policy covers alfecorona.com and exposure.alfecorona.com. Good-faith reports are welcomed when they minimize harm and respect privacy.
How to report
Email alfe@alfecorona.com with the affected URL, a concise description, safe reproduction steps, and potential impact. Do not include credentials, personal data, customer data, or exploit code unless requested through a protected channel.
Safe research boundary
Use only accounts and data you control. Do not perform denial of service, social engineering, phishing, persistence, destructive testing, automated high-volume scanning, or access beyond the minimum needed to demonstrate the issue.
Response posture
Reports are triaged for scope, reproducibility, exposure, and user impact. Credible issues are contained, corrected, validated, and documented before closure. Acknowledgment and remediation timing depend on severity and complexity; no bounty is offered.
Good-faith commitment
Good-faith research that follows this policy will not be treated as malicious. This commitment does not authorize privacy violations, third-party testing, illegal activity, or actions that disrupt service.
Machine-readable contact
The RFC 9116 record is available at /.well-known/security.txt. It identifies the canonical disclosure contact and this policy without exposing internal operational details.