Security
Found something? Tell us.
If you have found a security problem in this site, this page is how to reach us and what to expect once you do.
Last updated: 21 August 2026
Unreviewed draft
This document is a working draft. It has not been completed with VIHA COLLECTIVE's registered details and has not been reviewed by a lawyer, so it is not yet binding on anyone. Please do not rely on it. For any question about your data in the meantime, use the contact page.
How to report it
Email connect@vihacollective.com with enough detail for us to reproduce it — the URL, what you did, and what happened. If it is sensitive, say so in the first line and we will find a better channel before you send the details.
The same address is published at /.well-known/security.txt, so an automated scanner finds it too.
What we will do
- Acknowledge your report within five working days.
- Tell you whether we consider it a real issue, and if not, why — rather than going quiet.
- Fix what we agree is a problem, and tell you when it is done.
- Credit you by name if you would like, once it is fixed. We will not name you without asking.
We do not run a paid bounty programme. This is a small studio's site and we would rather say that plainly than imply a reward we will not pay.
What we ask of you
- Give us a reasonable chance to fix it before telling anyone else.
- Do not access, change or delete anyone else's data. If you come across personal data, stop and tell us.
- Do not run tests that degrade the site for other people — no denial of service, no bulk automated scanning, no social engineering of the studio.
- Stay within this site. Our email, our hosting and our other suppliers each have their own disclosure programmes.
Report in good faith and within the above, and we will not pursue you for it.
Out of scope
Findings from an automated scanner with no demonstrated impact, missing headers that cannot be exploited on a site with no login, version-disclosure banners, and issues in third-party services we do not operate. If you think a scanner finding is genuinely exploitable here, show us how and we will treat it as in scope.