← All policies

Securityand Disclosure

How we protect this website, and how to tell us about a weakness.

Last updated 1 October 2026 · In effect from 1 October 2026

01How we approach security

  • Minimal data. The public pages collect no accounts, passwords or forms, so there is very little to expose.
  • Separate private area. The staff area is not part of the public experience and requires an approved account.
  • Self-served assets. Fonts and images come from this website, not from third-party scripts.
  • Nothing from other companies loads until you ask. The only embed, a YouTube player, waits for you to press play.

No website can promise perfect security. We would rather hear about a problem than miss it.

02Report a vulnerability

Email aetheriszw@gmail.com with the subject "Security". Tell us:

  • what you found and where;
  • the steps to reproduce it;
  • what you think the impact is;
  • how we can reach you.

We aim to acknowledge your report within 5 working days, keep you informed, and tell you when it is fixed.

03What is in scope

  • In scope: this website, aetheriszw.company.
  • For Scholastic Services, Vimera or Nexus, report to the same address and name the product. Those products have their own scope and handling.
  • Out of scope: denial-of-service attacks, social engineering of our staff or users, physical attacks, and the third-party platforms we link to.

04Good-faith research

If you act in good faith, we will not take action against you for research that stays within this policy. That means you:

  • do not access, change or keep other people's data;
  • do not disrupt the website or damage anything;
  • give us a reasonable chance to fix the problem before you tell anyone else;
  • do not demand payment as a condition of reporting.

We do not run a paid bug bounty. We will credit you if you would like that.