Security Policy
Last updated 19 July 2026
This is a plain-language summary; the scope and promises below are what actually applies.
Reporting a vulnerability
Email contact@curltact.com with the subject line
Security. Please include:
- what the issue is, and what an attacker could do with it;
- the steps to reproduce it, including the exact request or card address;
- anything you need us to know to reproduce it safely.
We aim to acknowledge a report within 5 business days and to tell you what we intend to do within 30 days. Please read those as honest intentions rather than a contractual promise.
Our commitment to you
If you make a good-faith effort to follow this policy while researching and reporting:
- we will not bring a legal claim against you, or refer you to law enforcement, over the research;
- we will treat your report as authorised conduct under computer-misuse laws and our Terms of Service, so the parts of our Acceptable Use Policy that prohibit probing the Service do not apply to you for that work;
- we will work with you to understand and fix the issue quickly;
- we will credit you publicly if you want the credit, and stay quiet about you if you do not.
If a third party brings an action against you for research that followed this policy, we will make it known that your conduct was authorised.
What we ask of you
- Give us time. Please do not disclose publicly until we have had a reasonable chance to fix it, or 90 days have passed, whichever comes first.
- Use your own account and your own card for testing wherever possible.
- Do not access, modify, or delete other people's data. If you can prove the issue with one record, stop there. Do not exfiltrate anything, and tell us what you saw.
- Do not degrade the service. No denial-of-service, no load or stress testing, no automated scanning at volume. This runs on a small server.
- No social engineering, phishing, or physical attacks against us or anyone else.
- No spam or extortion. Reports demanding payment as a condition of disclosure are not welcome and will be treated as extortion, not research.
Scope
In scope: curltact.holtzhost.com, the cards it serves, the edit portal, and the
sign-in flow.
Out of scope, because they are not ours to authorise testing against: GitHub, GitLab, Paddle, and our hosting provider. Report issues in those to the companies concerned, under their own policies. Also out of scope: findings from automated scanners with no demonstrated impact, missing hardening headers with no exploit path, best-practice opinions about our TLS or DNS configuration, and social-engineering scenarios.
No bounty, and we would rather say so
We do not pay for vulnerability reports. curltact is an independent project with no revenue to speak of, and promising money we do not have would be worse than being upfront. What we can offer is a fast fix, real credit, and genuine thanks. If that is not worth your time, we understand completely.
What we do on our side
We keep the attack surface small on purpose. We store no passwords: sign-in is through GitHub or GitLab, so there is no password database to steal. We never see or store card numbers; Paddle handles payment. Traffic is served over HTTPS. We collect as little personal data as the product can work with, which is described in our Privacy Policy.
No system is perfectly secure, and we do not claim otherwise. If we discover a breach affecting your personal data, we will investigate promptly and notify affected users and any regulator that the law requires us to notify, within the time the law allows.
Contact
Security reports: contact@curltact.com, subject line
Security.
See also our Terms of Service, Acceptable Use Policy, and Privacy Policy.