1. Our Commitment
Digital Liberty values good-faith security research that helps protect readers, contributors, sources, editorial systems, and other technology controlled by the publication.
This policy explains how researchers can report suspected security vulnerabilities affecting Digital Liberty systems and the conditions under which authorized research may be treated as good-faith security testing.
This policy does not grant permission to access third-party systems, disrupt services, obtain unrelated information, or violate applicable law.
When the appropriate scope is uncertain, researchers should stop testing and contact:
before proceeding.
2. Scope
In scope are digitalliberty.info and any subdomains, applications, systems, or services that Digital Liberty expressly identifies as being controlled by the publication.
Third-party hosting, analytics, payment, advertising, content delivery, social media, email, embedded services, and other externally operated systems are outside the scope of this policy unless Digital Liberty explicitly confirms otherwise.
If a report concerns a third-party provider but may materially affect Digital Liberty users, researchers may send a minimal description of the issue.
Digital Liberty may coordinate with the relevant provider where appropriate, but this policy does not authorize security research or testing against systems controlled by that provider.
3. Good-Faith Research Conditions
Researchers should make a genuine effort to avoid privacy violations, destruction of data, service degradation, financial harm, and access beyond what is reasonably necessary to demonstrate a suspected vulnerability.
Use the smallest practical proof of concept.
If sensitive information is encountered unexpectedly, stop testing and do not retain, copy, publish, or share information that is unnecessary to demonstrate the vulnerability.
Researchers must not:
- Exploit a vulnerability beyond the level reasonably necessary for verification
- Establish persistence or maintain unauthorized access
- Pivot into unrelated systems
- Alter or delete website content or system data
- Access private editorial material
- Read confidential source communications
- Download databases or bulk datasets
- Perform denial-of-service or destructive testing
- Send spam or excessive automated requests
- Conduct phishing or social engineering
- Test physical security without explicit authorization
- Upload malware or malicious payloads
- Demand payment as a condition of withholding disclosure
4. Safe-Harbor Statement
Where security research is conducted in good faith, remains within the scope of this policy, avoids unnecessary harm, and is reported promptly through the disclosure process, Digital Liberty will not initiate legal action solely because the researcher performed activity authorized by this policy.
If a third party initiates action and the research complied with this policy, Digital Liberty may, where appropriate and lawful, clarify that the activity was conducted as part of its vulnerability disclosure process.
This safe harbor does not bind third parties, regulators, or law enforcement authorities.
It does not protect malicious, extortionate, reckless, deliberately harmful, out-of-scope, or otherwise unlawful conduct.
5. How to Report
Security reports should be sent to:
Please use the subject line:
Security vulnerability report
Where possible, include:
- The affected URL, application, system, or asset
- The type of vulnerability
- Steps required to reproduce the issue
- Observed and potential impact
- Date and time of testing
- Relevant browser, operating system, tool, or environment information
- A proof of concept that minimizes exposure
- Any suggested remediation or mitigation
Do not attach large databases, private messages, identity documents, credentials, or unnecessary personal information.
If sensitive evidence is necessary, request an encrypted communication channel before sending it.
Digital Liberty should maintain a valid /.well-known/security.txt file identifying the current security contact, policy URL, preferred language, and relevant expiry information.
6. Response Targets
Digital Liberty aims to:
- Acknowledge credible security reports within three business days
- Provide an initial assessment within ten business days
- Communicate material status changes while remediation is underway
These are response targets rather than guarantees.
Complex vulnerabilities, third-party dependencies, holidays, active incidents, infrastructure limitations, or other circumstances may require additional time.
Vulnerabilities may be prioritized according to exploitability, affected data, potential user impact, required privileges, affected scope, persistence, and availability of mitigations.
7. Coordinated Disclosure
Researchers should allow a reasonable period for assessment and remediation before publicly disclosing a vulnerability.
Digital Liberty will seek to discuss an appropriate disclosure timeline in good faith.
Immediate public disclosure may be justified in exceptional circumstances where users face active harm and the publisher is unresponsive.
However, unnecessary publication of exploit details, credentials, private information, or operational security details can increase risk and should be avoided.
Digital Liberty may credit a researcher with their consent after remediation.
The publication does not promise payment, a bounty, employment, public recognition, or other compensation unless such terms have been agreed in writing before the claim is made.
8. Out-of-Scope Findings
The following are generally outside the scope of this disclosure process:
- Missing security headers without demonstrated security impact
- Clickjacking on pages without sensitive actions
- Self-XSS
- Rate-limit observations without meaningful exploitation or impact
- Automated scanner results without validation
- Username enumeration without additional security impact
- Email authentication observations without evidence of exploitability
- Vulnerabilities existing solely within unsupported third-party components not controlled by Digital Liberty
An issue being classified as out of scope does not necessarily mean that it has no security value.
Digital Liberty may still review an out-of-scope finding where the reported evidence indicates a credible risk to users, systems, or confidential information.
9. Incident and Privacy Handling
Security reports may be shared only with individuals, service providers, or professional advisers who reasonably need the information for security assessment, remediation, legal compliance, insurance, or incident response.
Security records may be retained for security, accountability, audit, and legal purposes.
Personal information contained in a security report should be minimized and handled in accordance with the Privacy Policy.
Researchers should avoid including unnecessary personal or confidential information in vulnerability reports.
10. Contact
Security reports:
security@digitalliberty.info
Privacy concerns unrelated to a vulnerability:
privacy@digitalliberty.info
Editorial safety or source-security concerns:
editorial@digitalliberty.info
For security vulnerabilities, researchers should use the dedicated security address wherever possible so that reports reach the appropriate responsible function promptly.
Last reviewed: 24 August 2026.
