Skip to content

Security · Updated September 12, 2026

Report a security issue.

Send suspected vulnerabilities affecting nickcerutti.com to n@nickcerutti.com with the subject Security report.

What to include

Describe the affected URL, the issue, its potential impact and the minimum steps needed to reproduce it. Include your preferred reply address. Redact credentials, personal data and client information. Contact Nick before sending material that needs an encrypted channel; no dedicated encryption key is currently published.

Scope and safe handling

This reporting channel covers nickcerutti.com. It does not authorize testing of client systems, email accounts, booking providers, hosting infrastructure or repositories with separate security policies. Do not perform denial-of-service testing, social engineering, destructive actions or access data that is not yours. If you encounter unexpected access to data, stop and report the minimum information needed to explain the issue.

Coordinated disclosure

Please report privately so the issue can be assessed and addressed, and coordinate any public disclosure with Nick. Reports are reviewed according to their impact. This page does not promise a response deadline, a paid bounty or authorization to conduct intrusive testing.

Machine-readable contact

The canonical security contact file is available at https://nickcerutti.com/.well-known/security.txt. Its expiry date is maintained separately from the website deployment date.

Contact

Website operator: Nick Cerutti. n@nickcerutti.com