01How we approach security
- Minimal data. The public pages collect no accounts, passwords or forms, so there is very little to expose.
- Separate private area. The staff area is not part of the public experience and requires an approved account.
- Self-served assets. Fonts and images come from this website, not from third-party scripts.
- Nothing from other companies loads until you ask. The only embed, a YouTube player, waits for you to press play.
No website can promise perfect security. We would rather hear about a problem than miss it.
02Report a vulnerability
Email aetheriszw@gmail.com with the subject "Security". Tell us:
- what you found and where;
- the steps to reproduce it;
- what you think the impact is;
- how we can reach you.
We aim to acknowledge your report within 5 working days, keep you informed, and tell you when it is fixed.
03What is in scope
- In scope: this website, aetheriszw.company.
- For Scholastic Services, Vimera or Nexus, report to the same address and name the product. Those products have their own scope and handling.
- Out of scope: denial-of-service attacks, social engineering of our staff or users, physical attacks, and the third-party platforms we link to.
04Good-faith research
If you act in good faith, we will not take action against you for research that stays within this policy. That means you:
- do not access, change or keep other people's data;
- do not disrupt the website or damage anything;
- give us a reasonable chance to fix the problem before you tell anyone else;
- do not demand payment as a condition of reporting.
We do not run a paid bug bounty. We will credit you if you would like that.
