Security / Last updated 21 September 2026
Security
Report a vulnerability
Email security@basenodelab.com with the affected URL or system, a concise description, reproduction steps, likely impact, and a safe contact method. If sensitive details require encryption, ask for a secure channel before sending them.
Coordinated disclosure
Give us a reasonable opportunity to investigate and fix a report before public disclosure. We will acknowledge useful reports when practical, keep communication focused on remediation, and tell you if a different operator owns the affected system.
Safe testing boundaries
Good-faith research must avoid privacy violations, data destruction, persistence, social engineering, denial of service, automated high-volume scanning, access to client environments, and use of a finding beyond what is needed to demonstrate it. Stop if you encounter personal, client, or confidential data, and report what happened.
What we can promise today
- HTTPS is required for the public site and certificates renew automatically.
- The site ships without third-party analytics or advertising scripts.
- DNSSEC protects the current authoritative DNS chain.
- Security reports have a dedicated mailbox.
We do not claim certifications we have not earned. Statements about client systems, uptime, recovery, access controls, or compliance appear only in a project-specific scope backed by evidence.
Response expectations
This is a small independent studio, not a staffed 24-hour security operations centre. We triage credible reports as quickly as practical; immediate acknowledgement is not guaranteed. For an active threat to a third-party service, contact that service's operator as well.
Machine-readable disclosure details are available at /.well-known/security.txt.