Security & vulnerability disclosure
DechoNet checks other sites' security, so we should be held to the same standard. If you find a vulnerability, please tell us.
How to report
- Email: support@dechonet.com (start the subject with [security])
- Tell us what you found, the steps that led to it and what it affects. A reproduction gets it fixed fastest.
- If you saw a screen or response containing personal data, do not send that data — tell us where it appeared.
What we promise
- We acknowledge within 3 business days and tell you our assessment and fix plan.
- We will not take legal action against good-faith research that follows this page.
- After a fix, we credit you on request. There is no bounty programme at the moment.
In scope
- dechonet.com and its paths (public tools, API, account and monitoring screens, the MCP endpoint)
- The public npm package dechonet-mcp and the GitHub Action node-man/dechonet-gate
Please do not
- Run denial-of-service, high-volume requests or automated mass scans. Public tools are rate limited.
- Access or change other users' accounts or data. Stop at the minimum needed to show the issue and tell us.
- Try to reach another case in the investigator workspace — if you find a way, stop and tell us at once.
- Use social engineering, physical attacks, or test the third-party services we run on (Cloudflare, AWS, Resend and others).