Disclosure
Security Policy
This is a personal portfolio site. It is statically generated, has no user accounts, no database, and stores no visitor data. Reports are still welcome, and I will read every one of them.
// NO BOUNTY
There is no bug bounty program here and no monetary reward of any kind. I am a student running this site personally. Reports sent with an invoice, a payment demand, or a request for compensation will be closed without a reply. If that is a dealbreaker for you, please do not spend your time on this site.
In scope
- +riskyakbar.my.id and its subdomains
Out of scope
- -Third party services linked from this site (GitHub, LinkedIn, Instagram, Credly)
- -The hosting platform itself; report those to Vercel
- -Any system that is not owned by me
Rules of engagement
- !Do not run automated scanners, fuzzers, or brute force tools against this site.
- !Do not attempt denial of service, or anything that degrades availability for others.
- !Do not attempt social engineering, phishing, or physical access.
- !Do not access, modify, or exfiltrate data that is not yours.
- !Stop as soon as you have proof of concept, and report it.
Reports I will not action
These are common on static sites and carry no real impact here:
- xRaw output from automated scanners with no demonstrated impact
- xMissing SPF, DKIM, or DMARC records; this domain does not send email
- xClickjacking on pages with no state changing actions
- xMissing security headers with no working exploit path
- xBest practice suggestions that do not describe a concrete attack
- xDisclosure of information that is already public by design, such as my contact address
How to report
Email me with the affected URL, the steps to reproduce, and what an attacker could actually achieve. Proof of concept code or a short screen recording helps. English or Indonesian are both fine.
I aim to acknowledge valid reports within seven days. Please give me reasonable time to fix an issue before publishing it. I am happy to credit you once it is resolved.