Security

Report vulnerabilities without creating new harm.

Good-faith reports that help protect readers and infrastructure are welcome. Please keep testing bounded, non-destructive, and respectful of other people’s data.

How to report

Email editor@qaeda.org with the affected URL, a concise description, reproducible evidence that does not expose private data, and the impact you believe the issue could have.

Testing boundaries

  • Do not access, alter, retain, or publish other people’s private data.
  • Do not use denial-of-service, destructive payloads, persistence, social engineering, credential stuffing, or spam.
  • Do not test third-party systems merely because QAEDA links to them.
  • Stop when you have enough evidence to demonstrate the issue safely.

Scope

The public QAEDA.org application and its deployment configuration are the intended scope of this policy. AL.QAEDA.ORG is a related subdomain with its own published scope and should not be assumed to share this policy unless it says so.

What to expect

This project does not currently advertise a bug-bounty or payment program. A report should be judged on technical evidence and user impact rather than on public pressure. Security fixes may require hosting-provider or deployment-level changes that are outside the repository itself.

Machine-readable contact

The canonical security contact file is available at /.well-known/security.txt.