Skip to content
←Back to the portfolio

Site policies · Goh Kun Ming

Security and vulnerability reporting

How to report a suspected issue safely, with clear boundaries and no unsupported promises.

Updated: 2026-10-08

These notices describe the current portable release. Hosting details must be added before public launch.

On this page

  1. Report an issue privately
  2. Scope and safe conduct
  3. Handling reports
  4. Current security boundaries

Report an issue privately

If you believe you have found a security weakness in this portfolio, email kunmingaden@gmail.com with the subject Portfolio security report. Describe the affected page or feature, what you expected, what happened, and the smallest steps needed to reproduce it. Include your browser and approximate time where relevant.

Share only the evidence needed to understand the issue. Remove passwords, tokens, personal information and unrelated data from screenshots or logs. Start with a short description if the details are sensitive; do not send secrets or active malicious attachments through ordinary email. No public encryption key is currently designated by this policy.

Scope and safe conduct

This reporting channel covers the portfolio's own pages and application code. It does not authorise testing of its hosting provider, email service, linked repositories, employers, schools or other third-party systems. Those operators have their own reporting channels and rules.

Please use the least intrusive method that establishes the issue. Stop if testing would expose another person's information, change data you do not own or affect availability. Do not perform denial-of-service testing, bulk scanning, social engineering, credential attacks or persistent access. Obtain specific permission before active testing that goes beyond normal use of the public pages.

This policy is an invitation to report observations, not a general authorisation to access systems or a legal safe-harbour agreement. It does not create a bug bounty or promise payment, public credit or immunity from a third party's actions.

Handling reports

Reports can help reproduce and assess a weakness and identify an appropriate correction. Relevant details may need to be shared with a service provider or component maintainer involved in resolving it. Please identify any information you would prefer not to have shared and avoid including unnecessary personal details.

Please allow a reasonable opportunity to investigate before publishing exploit details, and discuss disclosure timing through the same contact channel. This personal portfolio does not offer round-the-clock incident response or a guaranteed acknowledgement, repair or disclosure deadline. Any legal duties that apply to an incident remain unaffected.

Current security boundaries

The default static site has no login, payment system, upload service or database-backed form. The prepared AWS live guide uses server-side execution permissions; visitors receive no provider credentials. It limits request size, conversation context, model calls and shared usage. Its search tool reads reviewed public portfolio material, not arbitrary private files or websites. Input, output and source checks reduce risk but cannot guarantee factual accuracy or prevent every abuse. Local history and settings stay in browser storage. Optional audio uses no microphone or remote audio service.

Source reviews and local automated checks describe only a tested version; they do not certify security or establish that every vulnerability has been found. The prepared AWS controls include restricted origin access, security headers and shared abuse and budget counters. Live AI remains disabled pending provider, logging and deployed checks. Public HTTPS, DNS, headers, permissions and control behavior need separate verification before activation. Keep your browser updated and avoid confidential information in either guide mode.

Download policy handbook (PDF)

The web edition is recommended for reading and assistive technology.

PrivacyTermsSecurityAccessibility Third-party notices

Independent portfolio. Not an official Minecraft website. Not approved by or associated with Mojang or Microsoft.

Leave this world?

You are opening another website.

Destination
Full link