Vulnerability Disclosure Policy

Published: 20 July 2026 · Machine-readable version: /.well-known/security.txt

We build verification and accountability tools, so we take reports about our own security seriously.

If you believe you have found a vulnerability in an Aramantos Digital product or service, we want to hear from you.

How to report

Email security@aramantos.dev (or support@aramantos.dev, both reach us) with what you found, where, and how to reproduce it.

If it is sensitive, ask for a secure channel in your first mail and we will arrange one.

What we promise

Safe harbour

If you make a good-faith effort to avoid privacy violations, data destruction and service disruption while researching, and you give us reasonable time to remediate before public disclosure, we will not pursue legal action over your research.

Do not access other people's data, and do not run denial-of-service tests.

Scope

Any service under aramantos.dev and our product domains, plus our published packages.

What we do not offer

We are a small company and do not currently run a paid bug bounty.

What we offer instead is fast, honest handling and a verifiable public record of your disclosure if you want one.