Found a security problem? Tell us.
Empirq LLC values the work of security researchers. If you find a vulnerability in Empirq, we want to hear it from you directly, not discover it some other way. This policy sets out how to reach us, what we consider in scope, what we ask you not to do, and what happens after you report.
Last updated: September 16, 2026
This is not a bug bounty program. We do not pay for reports.
1. How to report
Email [email protected]. Please include enough detail for us to reproduce the issue: the affected URL or endpoint, the steps you took, and what you were able to achieve. A short proof of concept is worth more than a long description.
Use test accounts and your own data wherever possible. If a finding requires touching another person’s account or content to demonstrate, stop and describe it instead. We will work through it with you.
Our machine-readable contact details are at /.well-known/security.txt, current until June 30, 2027.
2. What to expect
Empirq is a small team, so replies come from a human, not a queue. We aim to acknowledge a report within a few business days, and we will tell you plainly whether we consider it a vulnerability, what we intend to do, and roughly when.
We do not run a bug bounty and do not pay for reports. We would sooner say so here than leave it unstated. What we can offer is public credit: if you would like to be named once a fix has shipped, tell us how you would like to be credited.
Please give us a reasonable opportunity to fix an issue before disclosing it publicly. Unless we agree otherwise, we ask that you hold off until the fix has shipped or 90 days have passed since we acknowledged your report, whichever comes first. If something is being actively exploited, tell us and we will move faster together.
Whatever the timeline, please never publish another person’s data, credentials, or private content.
3. In scope
- empirq.com and its subdomains serving the production application
- The Empirq web application: authentication, publishing, subscriptions, and payments flows
- The Empirq API under empirq.com/api, including endpoints that require an account
4. Out of scope
Not because these do not matter, but because testing them costs us more than it tells us.
- Staging and other non-production environments.
- staging.empirq.com sits behind HTTP Basic Auth and is not a target. Findings there are not eligible.
- Our infrastructure below the application.
- Origin servers, SSH, containers, databases, and caches are not intentionally exposed. Report anything that reaches them, but please do not go looking.
- Scanner output with no demonstrated impact.
- Raw findings from automated tools, missing headers, or version fingerprints without a working exploit path.
- Our vendors' infrastructure.
- Stripe, Cloudflare, DigitalOcean, and Resend run their own programs. Report issues in their systems to them directly. A problem in how we have configured or integrated one of them is ours, and we do want to hear about it.
5. Please don't
Testing that would hurt someone other than us, whatever it might prove.
- Degrade the service.
- No denial of service, load testing, traffic floods, or resource exhaustion. Real readers and writers are using this.
- Touch anyone else's data.
- Do not read, copy, change, or delete another person's content, account, or subscriber information. If a finding seems to require it, stop and describe it instead.
- Send anything to our users.
- Do not trigger newsletters, notifications, or any other message that reaches real readers and writers. Their inbox is not a test surface.
- Create real money movement.
- Do not deliberately cause charges, refunds, disputes, or chargebacks. A dispute has consequences for the writer, not just for us. Ask us first if a payment finding needs one to demonstrate.
- Social engineering.
- No phishing or pretexting aimed at Empirq, our writers, or our readers. Please do not contact writers as part of testing.
- Brute force or reuse stolen credentials.
- No credential stuffing, password spraying, or credentials from breach dumps. Use accounts you own.
- Bulk-create accounts or content.
- A handful of test accounts is fine. Automated mass signup is not.
- Persist, spread, or hunt for our origin.
- No backdoors or persistence, no moving sideways into other systems, and no attempts to find our origin addresses or work around the CDN in front of them.
If you are unsure whether something here is allowed, ask us first. We would rather answer a question than read an apology.
6. Usually not a vulnerability on its own
Send these if you can show real impact. Without it we will probably not action them, and we will say so instead of leaving you waiting.
- Missing security headers with no working exploit
- Version disclosure, or TLS configuration advice, with nothing exploitable behind it
- Self-XSS that cannot reach another user
- Open redirects with no meaningful impact
- Username or email enumeration with no sensitive disclosure attached
- Rate-limit suggestions with no demonstrated bypass
- Raw scanner output nobody has validated
7. Safe harbour
If you conduct good-faith security research in accordance with this policy, Empirq will treat that research as authorized for purposes of claims that Empirq itself could assert under the Computer Fraud and Abuse Act and, to the extent applicable, the anti-circumvention provisions of the DMCA. Empirq will not initiate or support legal action against you, or report you to law enforcement, based solely on research conducted in compliance with this policy.
To rely on this safe harbor, you must comply with this policy, including by: stopping as soon as you have confirmed a vulnerability; not accessing or testing any system beyond what is reasonably necessary to demonstrate the vulnerability; not intentionally accessing, modifying, deleting, copying, disclosing, or retaining data belonging to another person; promptly deleting any such data encountered incidentally; not degrading the service for others; not causing harm to Empirq, its users, or any third party; reporting the vulnerability promptly; and withholding public disclosure in accordance with the timeline in Section 2 above.
This safe harbor applies only to claims that Empirq itself has authority to bring or waive. It does not authorize access to systems or data owned or controlled by Empirq's service providers or any other third party, bind any service provider or other third party, or apply to conduct that is unlawful independent of this policy. Empirq reserves all rights and remedies with respect to any activity that is not conducted in good faith and in accordance with this policy.
Good-faith mistakes. Research involves uncertainty. An accidental and limited overstep will not necessarily disqualify you from this safe harbor if you were genuinely attempting to comply with this policy, stopped promptly, reported the overstep to us, cooperated in limiting any harm, and did not use or disclose any data or access obtained as a result. We will consider the nature and severity of the conduct, your intent, the actual or potential harm, and your efforts to prevent and mitigate that harm. This safe harbor does not cover intentional or reckless violations of this policy; concealment of an overstep; exploitation of a vulnerability beyond what is reasonably necessary to demonstrate it; extortion; fraud; disruption; theft; harassment; social engineering; unauthorized persistence; data exfiltration; privacy violations; financial misconduct; or any attempt to profit from, threaten, or harm Empirq, its users, or any third party.
8. Not a security issue?
For privacy questions see our Privacy Policy. For anything else, [email protected] is the right address. Reports sent to [email protected] that are not security-related will simply be forwarded, so nothing is lost either way.
9. Changes to this policy
We may update this policy as the product and our practices change. Testing is governed by the version published when the testing occurs, unless we agree otherwise in writing.