Security
Effective · 4 August 2026
If you find a weakness in this site, we want to hear about it — and we will treat good-faith research in good faith.
Scope
dineshkp.com. The honest posture: this is a wholly static site served from Cloudflare Pages. There are no API endpoints, no server-side code, no database, no accounts, no payments, and no personal data stored by us at all. The surface is about as small as a website's gets — but we still want to know when it cracks.
What runs in your browser
One third-party service: Google Tag Manager, and only if you accept the analytics notice. Decline and no third-party code is loaded. Everything else — fonts, styles, scripts — is served from this domain.
Responses carry a Content Security Policy that permits scripts only from this origin, from Google's tag domains, and from a fixed list of hashes; plus HSTS, frame-ancestors and X-Frame-Options denial, and a restrictive Permissions-Policy. Reports of ways around any of these are in scope and welcome.
How to report
Email contact [at] dineshkp [dot] com with a subject line starting “SECURITY”. Include what you found, where, and the steps to reproduce it. If you'd like credit when it's fixed, say so — we're glad to give it. There is currently no monetary bounty program.
What to expect
Acknowledgement within 72 hours, an honest assessment of severity, and a note when it is fixed. We ask for a reasonable window — 90 days is the convention — before any public disclosure.
Ground rules
- Test against your own browser session only.
- Do not attempt to access, modify, or delete data that is not yours.
- No denial-of-service, spam floods, or automated scanning at disruptive volume.
- No social engineering, phishing, or physical attacks.
- Findings in Cloudflare's or Google's own infrastructure belong to their disclosure programmes, not ours.
Good faith, both ways
Research that stays within these rules is authorized use of the site. We will not pursue legal action against researchers who follow this policy, and if a third party does, we will make it known the research was authorized.
Machine-readable version
This policy is summarised at /.well-known/security.txt, per RFC 9116.