Email security@publifye.com. Please include enough detail to reproduce. We will acknowledge receipt and keep you informed while we work on it.
Please do not open a public issue for a suspected vulnerability.
This repository contains documentation and metadata only — no server code. Reports about the hosted services themselves are in scope:
https://darash-api.publifye.comhttps://junifye.publifye.comhttps://lexifye.publifye.comhttps://brreg.publifye.comhttps://lighthouse.publifye.pro(authorisation server)
Please do not run automated scanning or load testing against these endpoints. If you need to test something that looks like abuse, write to us first and we will arrange it.
We will not ask you to sign anything before we fix a reported issue, and we will not object to you publishing your findings after a fix has shipped.