Responsible Disclosure
Found a bug in our own site?
FalehSec is a security firm, so falehsec.dev gets the same treatment we give clients — hardened headers, Turnstile on every form, minimal data, and a real person reading every message. Found something anyway? We appreciate responsible reports.
How to report
Email m45faleh@falehsec.dev with: what you found, the steps to reproduce, and the impact you think it has (a proof-of-concept is welcome). Keep it private — please don't disclose it publicly before we've had a chance to respond.
- Scope is falehsec.dev (and its pages) — not third-party links like LinkedIn or external services.
- We confirm receipt within 24 hours and share a status update as we fix it.
- With your permission, we're glad to credit you publicly. We don't run a paid bounty program yet — this one is on the house.
What we already run here
- A+ security headers — HSTS (preload), strict CSP, nosniff, frame DENY, permissions policy, COOP/CORP. Verifiable on public scanners.
- Turnstile on every form — the chat and the contact form both require a silent one-time browser challenge; scripted floods are rejected.
- No tracking cookies, no analytics — only a cookieless visit counter with no personal data.
- One inbox, minimal retention — see the Privacy Policy for exactly what we keep.
- Public
security.txt— this exact page's disclosure file.
Good-faith rules
- Don't access or copy other visitors' data — test only what you need to prove the issue.
- No denial-of-service, spam, or automated flooding of our own endpoints.
- Give us a reasonable window (we ask for 30 days) before public disclosure.
Prefer to just talk it through?
Whether it's a report about our site or a question about your own — the door is open: the assistant is bilingual, and booking a call is one click.