Skip to content

Legal

Reporting a vulnerability

Last updated 21 September 2026 · English is the governing language of this document.

How to report

Email our contact form. Please include enough detail to reproduce the issue. We will acknowledge within three working days.

We do not run a paid bug bounty. We are a small olive grove. We will thank you properly, credit you if you want to be credited, and fix the problem.

In scope

  • oliviuscreta.com and every subdomain of it
  • Our public APIs
  • Anything that could expose customer data or affect an order or a price

Out of scope

  • Findings from automated scanners with no demonstrated impact
  • Missing headers or best practices with no exploitable consequence
  • Denial of service, volumetric or otherwise
  • Social engineering of us, our family or our couriers
  • Anything requiring physical access to the grove

What we ask

Please do not access, change or delete data belonging to anyone else, do not degrade the service for customers, and give us a reasonable chance to fix things before publishing. Test against your own orders and your own data.

If you follow that, we will not pursue any legal action against you for your research.

A machine-readable version of this is published at /.well-known/security.txt.