Responsible disclosure

Report a suspected vulnerability.

For a suspected vulnerability involving this website or Strout Consulting LLC software, email security@stroutconsulting.com.

What to include

Provide enough detail to understand and reproduce the issue: the affected location, observed behavior, steps to reproduce, and potential impact. Do not send passwords, private keys, recovery codes, or unrelated personal information.

Research guidelines

  • Avoid accessing, changing, retaining, or sharing another person’s data.
  • Avoid privacy violations, service disruption, social engineering, and physical attacks.
  • Use only the minimum testing needed to demonstrate the issue.
  • Give us a reasonable opportunity to investigate before public disclosure.

Scope and expectations

This page provides a reporting channel. It is not a bug-bounty offer, promise of payment, or authorization to access systems or data. We will review reports received at the address above, but we do not promise a particular response or resolution timeline.