Public Site Posture
- No public login, database, CMS, contact form, or account system.
- No client-side secrets, third-party scripts, analytics pixels, cookies, or trackers.
- Static-host headers are included for CSP, framing protection, MIME sniffing protection, referrer limits, and permissions limits.
- Public project visuals are sanitized and do not contain live operational data.
Testing Rules
Do not attempt to access private systems, non-public endpoints, admin surfaces, employee accounts, cloud consoles, email accounts, repositories, or third-party providers without explicit written authorization.
Do not run denial-of-service tests, social engineering, phishing, credential attacks, persistence attempts, destructive scans, data exfiltration, or tests that could disrupt workers, vendors, collaborators, or public services.
Reporting
Send a concise report to olivia@allsystemsgreen.io with the affected URL, steps to reproduce, impact, and any safe proof of concept. Please do not include secrets or personal data.
No Public Bug Bounty
We do not currently operate a public bug bounty program. Reports are appreciated, but no reward, engagement, authorization expansion, or response timeline is promised unless agreed in writing.