This repository powers a single production deployment
(prashanthai.com). Only the main branch / latest
production deployment is supported with security fixes.
| Branch | Supported |
|---|---|
main |
✅ |
| other | ❌ |
If you discover a security vulnerability in this codebase or in prashanthai.com, please report it privately rather than opening a public GitHub issue.
- Email: hello@prashanthai.com
- Subject line:
[SECURITY] <short description> - Include: steps to reproduce, affected URL/route, potential impact, and (if applicable) a proof of concept.
We aim to acknowledge reports within 3 business days and to provide a resolution timeline within 10 business days. Please give us a reasonable period to address the issue before any public disclosure.
In scope:
- The Next.js application in this repository
- The deployed production site at prashanthai.com
Out of scope:
- Third-party services we depend on (Vercel, Cloudflare, Google Workspace) — please report issues in those platforms directly to their vendors
- Denial-of-service testing, spam/social engineering against staff, or physical security
This project does not currently run a paid bug bounty program. We are happy to credit researchers who responsibly disclose valid findings, with permission.