Security practice

Report safely. Verify claims with evidence.

FilthyGM separates public reporting instructions from restricted incident evidence, credentials, infrastructure, and affected-person data.

01

Reporting

Use the structured Contact security path. Include the affected surface, reproducible impact, and a safe way to reach you if you choose. Do not include live credentials, private user data, payment-card data, or exploit material in a public channel.

  • The current machine-readable policy is at /.well-known/security.txt
  • Security cases receive restricted routing
  • Good-faith reports are not routed into editorial coverage or marketing
02

Controls

High-risk commands require authenticated AAL2 staff roles, same-origin requests, idempotency, optimistic versions, reasons, command receipts, audit records, and independent approval where policy requires it. Hub mutations additionally require body-bound signatures, replay protection, and durable acknowledgement.

  • Least privilege and fail-closed configuration
  • Encrypted restricted fields and token hashes
  • Append-only audit and governance evidence
  • Rate limits, abuse controls, revocation, and bounded retention
03

Evidence boundary

A public security statement is not proof of production effectiveness. Release certification records automated checks, independent review, key-rotation evidence, incident exercises, dependency posture, and current exceptions without publishing exploitable detail.