The MachineRecord
Security

Reporting a vulnerability

If you find a way to break this, we would rather hear it from you than from someone else.

Effective 3 August 2026

Responsible disclosure

Report to security@themachinerecord.com. Include enough detail to reproduce the issue. Target first response is five days.

We will not pursue legal action against good faith research.Good faith means: you did not access other people's data beyond what proves the issue, you did not degrade the service for others, and you gave us a reasonable window before publishing.

How data is protected

transport
TLS everywhere, HSTS with preload.
passwords
None stored: sign-in is by email link.
database
Private network, access limited to the owner.
backups
Daily, encrypted at rest.
payments
Card details never reach our systems.
secrets
Encrypted at rest, private keys never committed to the repository.

Out of scope

  • Reports generated by an automated scanner with no demonstrated impact
  • Missing headers with no exploitable consequence
  • Denial of service through volume
  • Social engineering of the operator or third party providers