Reporting a vulnerability
If you find a way to break this, we would rather hear it from you than from someone else.
Effective 3 August 2026
Responsible disclosure
Report to security@themachinerecord.com. Include enough detail to reproduce the issue. Target first response is five days.
We will not pursue legal action against good faith research.Good faith means: you did not access other people's data beyond what proves the issue, you did not degrade the service for others, and you gave us a reasonable window before publishing.
How data is protected
- transport
- TLS everywhere, HSTS with preload.
- passwords
- None stored: sign-in is by email link.
- database
- Private network, access limited to the owner.
- backups
- Daily, encrypted at rest.
- payments
- Card details never reach our systems.
- secrets
- Encrypted at rest, private keys never committed to the repository.
Out of scope
- Reports generated by an automated scanner with no demonstrated impact
- Missing headers with no exploitable consequence
- Denial of service through volume
- Social engineering of the operator or third party providers