Security & vulnerability disclosure

DechoNet checks other sites' security, so we should be held to the same standard. If you find a vulnerability, please tell us.

How to report

  • Email: support@dechonet.com (start the subject with [security])
  • Tell us what you found, the steps that led to it and what it affects. A reproduction gets it fixed fastest.
  • If you saw a screen or response containing personal data, do not send that data — tell us where it appeared.

What we promise

  • We acknowledge within 3 business days and tell you our assessment and fix plan.
  • We will not take legal action against good-faith research that follows this page.
  • After a fix, we credit you on request. There is no bounty programme at the moment.

In scope

  • dechonet.com and its paths (public tools, API, account and monitoring screens, the MCP endpoint)
  • The public npm package dechonet-mcp and the GitHub Action node-man/dechonet-gate

Please do not

  • Run denial-of-service, high-volume requests or automated mass scans. Public tools are rate limited.
  • Access or change other users' accounts or data. Stop at the minimum needed to show the issue and tell us.
  • Try to reach another case in the investigator workspace — if you find a way, stop and tell us at once.
  • Use social engineering, physical attacks, or test the third-party services we run on (Cloudflare, AWS, Resend and others).

Methodology & accuracy · Privacy policy · security.txt