Security

Responsible disclosure for the Greywake public site.

Greywake welcomes clear, good-faith reports that help improve the safety and reliability of the public website and browser-based tools.

Clear reasoning. Practical controls.
Focused technology and tools for real operating environments.
Responsible disclosure

Report potential security issues directly and privately.

Email greywaketech@gmail.com with “Security report” in the subject. Include the affected URL, a clear description, reproduction steps, and potential impact. Do not include credentials, protected records, or unrelated personal information.

1

Use non-destructive testing and avoid accessing information that is not yours.

2

Provide enough detail to reproduce the issue without publishing it before review.

3

Allow reasonable time for investigation and remediation before public discussion.

Security posture

Reduce exposure before adding controls.

The public portfolio is browser-first, does not require accounts, and minimizes server-side application logic. Netlify response headers restrict framing, object loading, referrer leakage, unnecessary device capabilities, and external connections. Page-specific policies permit only the services required by selected tools.

No credential collectionPublic applications are not designed to receive passwords, private keys, tokens, or regulated records.
Restricted external callsNOAA, public IP, speed-test, and public API features use page-specific connection policies.
Local application stateMost working records remain in the browser unless the user exports a file.
Versioned deliveryProduction packages use controlled versions and checksums to support review and rollback.
Security contact

Potential vulnerability or unsafe behavior?

Send a private report →