Vulnerability disclosure policy
Good-faith research on Aikarai is welcome within these rules.
This policy authorizes bounded research on Aikarai itself. It does not promise a reward or universal legal immunity. Acknowledgment and any future reward are discretionary.
In scope
https://aikarai.com, its same-origin APIs and PWAs, and authorization isolation between accounts you created and control. www is limited to redirect and edge checks; staging is limited to its redirect and temporary signed-provider callback transition.
Never in scope
Vultr, GoDaddy, Titan, Resend, Stripe or Stripe-hosted Checkout, GitHub/GHCR, Grafana, third-party email providers, other users, social engineering, credential stuffing, denial of service, destructive load, persistence, malware, real cards, banks, payouts, or live-money objects.
Safe testing
Use only accounts and synthetic data you control, stay at or below five requests per second, use lower rates for authentication, email and uploads, stop if service health degrades, and stop immediately if you unexpectedly see another person’s private data. Retain only the minimum non-sensitive proof.