Reporting a vulnerability
How to report
Email our contact form. Please include enough detail to reproduce the issue. We will acknowledge within three working days.
We do not run a paid bug bounty. We are a small olive grove. We will thank you properly, credit you if you want to be credited, and fix the problem.
In scope
oliviuscreta.comand every subdomain of it- Our public APIs
- Anything that could expose customer data or affect an order or a price
Out of scope
- Findings from automated scanners with no demonstrated impact
- Missing headers or best practices with no exploitable consequence
- Denial of service, volumetric or otherwise
- Social engineering of us, our family or our couriers
- Anything requiring physical access to the grove
What we ask
Please do not access, change or delete data belonging to anyone else, do not degrade the service for customers, and give us a reasonable chance to fix things before publishing. Test against your own orders and your own data.
If you follow that, we will not pursue any legal action against you for your research.