Security and Responsible Disclosure

If you believe you have found a security issue on this site, we want to hear about it, and we will work with you in good faith to fix it.

How to report

Email security@demystifyingplm.com (or michael@demystifyingplm.com) with a description of the issue, the URL or endpoint affected, and the steps needed to reproduce it. Please report privately and give us a reasonable window to fix the problem before any public disclosure.

What to expect

  • An acknowledgement within 5 business days.
  • An honest assessment of the issue and, where it is valid, a timeline for the fix.
  • Credit for the finding once it is fixed, if you would like it.

Scope

In scope: www.demystifyingplm.com and its API routes. Out of scope: third-party services we link to or embed (YouTube, Stripe, podcast platforms), denial-of-service testing, social engineering, and reports generated purely by automated scanners without a demonstrated impact.

Safe harbour

We will not pursue legal action against anyone who reports in good faith, avoids privacy violations and data destruction, only accesses the minimum data needed to demonstrate the issue, and does not disrupt the service for other readers.

The machine-readable version of this policy is published at /.well-known/security.txt.

Back to DemystifyingPLM