Contact: mailto:nikhil@simplytics.dev Expires: 2027-03-04T17:57:30Z Preferred-Languages: en Canonical: https://simplytics.dev/.well-known/security.txt Policy: https://simplytics.dev/security # Simplytics is run by one person. There is no bug bounty and no payout, and # saying so plainly is fairer than letting anyone spend a weekend on the # assumption that there is one. Reports are read and answered. # # What is most worth your time, and what is not: # - The tracking beacons are cross-origin by design. They are posted from # customer websites; that is the product, not a misconfiguration. # - The Content-Security-Policy still allows 'unsafe-inline' for scripts. # This is known and written up on /security. A report that only says so # tells us nothing we have not already published. # - The api_key in a customer's page is public by design: it identifies a # site to the collector and grants no read access to anything.