Ciarán Paul Roche

Site / Security

Report a security problem.

A clear route for good-faith reports helps protect visitors, private contact messages and the work itself.

How to report

Use the contact form with “Security report” as the subject. Include the affected URL, a concise description, the impact, safe reproduction steps and a way to reach you. Do not include passwords, personal data belonging to other people or live exploit code in the first message.

Good-faith research

Avoid privacy violations, disruption, social engineering, denial of service, destructive testing and access to more data than is needed to demonstrate the issue. Stop if personal data is encountered. Allow reasonable time for investigation and correction before public disclosure.

Scope

This reporting route covers ciaranroche.com. Linked projects and third-party services have their own owners and reporting processes. There is no paid bug-bounty programme.

Published controls

The site uses encrypted transport in production, restrictive browser permissions, anti-framing and content-type protections, a content security policy, server-side validation, a honeypot and rate limiting on the contact form, and an owner-restricted inbox. No control eliminates all risk; reports are welcome.