FAQ
Security review FAQ
Common questions about security review, vulnerability triage, contact, privacy, and responsible disclosure.
Who is this for?
Readers and teams that need practical vulnerability context, source-linked research, or a clear handoff for bounded security work.
Is the public feed open?
Yes. New notes and coverage appear on the blog and public feed, and the homepage and news page surface the newest items for quick scanning.
Does the feed replace patch management?
No. It is informational. Validate each item against your own assets, vendor guidance, and change-control process.
How do I send responsible disclosure?
Use the contact page and include affected URL or asset, impact, and the safest reproducible steps you can share.