Vulnerability Disclosure Policy
Last updated: 2 October 2026
Not A Standard welcomes reports from security researchers. If you believe you've found a vulnerability in notastandard.org or its subdomains, we'd love to hear about it.
How to report
Email security@notastandard.org with "Security" in the subject line. Please include: the URL or component affected, steps to reproduce, and what you believe the impact is. Screenshots or a proof of concept are welcome. Plain text is fine; you don't need a formal template.
We'll acknowledge your report within 5 business days.
Scope
In scope: notastandard.org and its subdomains, including this site's content, configuration, and any forms or scripts we host.
Out of scope: GitHub's infrastructure (this site is hosted on GitHub Pages; report platform issues to GitHub directly), third-party services we link to, denial of service, social engineering of Not A Standard staff, and physical attacks.
This is a static website. We don't operate user accounts, authentication, or a backend on this domain, so findings in those categories don't apply here.
Our commitments
- We will not pursue legal action against researchers who act in good faith under this policy.
- We'll work with you to understand and resolve the issue.
- We'll credit you publicly if you'd like (or not, if you'd prefer).
- We don't currently run a bug bounty. Reports are appreciated but unpaid.
What we ask of you
- Don't access, modify, or exfiltrate data that isn't yours.
- Don't degrade the service for other visitors.
- Give us a reasonable time to fix the issue before disclosing it publicly. 90 days is our default; we're happy to talk if you need a different timeline.
- Stay within the law. Good faith research conducted under this policy is authorised by us for the purposes of this site; it doesn't authorise activity against anyone else's systems.
Safe harbour
Research that complies with this policy is considered authorised access by Not A Standard Pty Ltd. If a third party initiates legal action against you for activity that complied with this policy, we'll make it known that you were acting with our authorisation.
Acknowledgements
Oh no! None here yet!