Security

Effective August 26, 2026

Found something? Write to security@thevun.com. You do not need permission first, or a working exploit.

1. How to report

Email security@thevun.com with what you found, where, and what an attacker could do with it. Steps that reproduce it are the most useful thing you can send. The same address is in our security.txt.

2. Scope

This website, the services behind it, and the applications we publish. If you are not sure something is ours, report it anyway and we will tell you. And if you find something exposing data that should have stayed private, that is the report we want most.

3. What we ask

Give us a chance to ship a fix before you publish, and we will not ask you to sit on it indefinitely. Test against your own accounts and data only, and stop if you reach anyone else's. Leave people out of it: no social engineering, no physical access, no going after our staff or suppliers.

4. What to expect

A person reads every report and replies with what we think and what we intend to do. Because we write our own stack, the fix is ours to make rather than something we wait on an upstream for. That is Fix the code you control.

We do not run a paid bounty. We will credit you when we ship the fix, named however you prefer.

Research that stays inside the terms above is authorized as far as we are concerned, and we will not come after you for it.