# Vexxsus vulnerability disclosure # # The interesting attack surface here is small on purpose: the site is # static, the analysis engine runs in the visitor's browser, and no fill # data is transmitted. What we most want to hear about is anything that # breaks that — a way to make the page issue a request it should not, a # flaw in the vault's key handling (lib/vault.ts), or a way to recover an # account's figures from the pool payload (lib/pool.ts). Contact: mailto:security@vexxsus.com Expires: 2027-08-24T00:00:00.000Z Preferred-Languages: en, ru Canonical: https://vexxsus.com/.well-known/security.txt Policy: https://vexxsus.com/terms # Good faith research is welcome and we will not pursue it. Please give us # 90 days before publishing, do not access or alter anyone else's account, # and do not run automated scanning that degrades the service for others. # We have no bounty programme yet and will say so plainly rather than # implying one.