bugs.mux1337.de
Coordinated Disclosure Policy
Version 1.0 — 2026-09-09
1. How I report
- Reports go through the vendor's official channel (bug bounty portal, security contact, or
security.txt) — never through public issue trackers.
- Reports include reproduction steps and impact analysis, scoped to what is needed to validate the issue.
- I do not run exploits against production systems beyond what a program's rules explicitly authorize.
2. What I ask from vendors
- Acknowledgement and a case/tracking reference within 7 days.
- A remediation plan and an estimated fix date for confirmed issues.
- Credit if desired — or anonymity if preferred.
3. Publication timeline
- Status only (this site) is published as soon as a report is filed — no technical detail.
- Technical details are published after the earlier of:
- the vendor ships and confirms a fix in production, or
- 90 days after the report date (or longer if the vendor is actively working with me
and asks in writing for an extension).
- Before publishing, the vendor gets a final draft with at least 14 days notice.
- Where a program's own terms define stricter rules, the program's rules win.
4. Status definitions used on this site
- In preparation — analysis complete, report not yet filed.
- Reported — filed via the official channel; clock started.
- Under review — vendor acknowledged, triage ongoing.
- Fix in progress — vendor confirmed and is remediating.
- Resolved — details pending — fix confirmed live; write-up scheduled.
- Disclosed — full technical write-up published on this site.
5. Safe harbor
If you are a vendor: research I publish is performed within the target program's authorized scope and rules.
I will always provide a good-faith account of methodology and cooperate with validation. If you believe a line
was crossed, contact me via /.well-known/security.txt before any legal escalation —
I respond quickly.
6. Contact
See /.well-known/security.txt for the current
contact address and key rotation.