How to report
Send your report to security@slaborlaw.com. Please include:
- A description of the vulnerability and where it is (URL or page).
- Clear steps to reproduce it.
- Its potential impact if exploited.
- A way to contact you if we need clarification.
Our commitment to you
- We will acknowledge and respond to your report within 7 days.
- We will keep you informed of our fix plan and approximate timeline.
- We will take no legal action against anyone who reports in good faith and follows this policy.
- We will thank you publicly on our acknowledgments list once the issue is fixed, if you wish.
What we ask of you
- Do not access, modify or delete other people's data, and stop as soon as you reach any personal data.
- Do not perform denial-of-service, flooding or intensive automated scanning.
- Do not use social engineering or phishing against our team or users.
- Give us reasonable time to fix the issue before disclosing it publicly.
Scope
This policy covers slaborlaw.com and slaborlaw.net. Vulnerabilities in third-party services, such as our email provider or social media platforms, should be reported directly to their owners.