Use non-destructive testing and avoid accessing information that is not yours.
Responsible disclosure for the Greywake public site.
Greywake welcomes clear, good-faith reports that help improve the safety and reliability of the public website and browser-based tools.
Focused technology and tools for real operating environments.
Report potential security issues directly and privately.
Email greywaketech@gmail.com with “Security report” in the subject. Include the affected URL, a clear description, reproduction steps, and potential impact. Do not include credentials, protected records, or unrelated personal information.
Provide enough detail to reproduce the issue without publishing it before review.
Allow reasonable time for investigation and remediation before public discussion.
Reduce exposure before adding controls.
The public portfolio is browser-first, does not require accounts, and minimizes server-side application logic. Netlify response headers restrict framing, object loading, referrer leakage, unnecessary device capabilities, and external connections. Page-specific policies permit only the services required by selected tools.
