Legal
Security Policy
I welcome responsible disclosure of security issues. Please report vulnerabilities privately before public disclosure.
Effective date: August 24, 2026. This Security Policy applies to https://srujanchidarla.com, its API routes, and the optional Android/iOS app shell that loads this site.
Scope
- Website and subpages hosted at srujanchidarla.com
- Serverless API routes (/api/chat, /api/github/*, /api/dsa-activity)
- Capacitor mobile app that loads the production website
Out of scope
- Third-party services (Vercel, Anthropic, GitHub, Google Calendar) — report to them directly
- Social engineering, phishing, or physical attacks
- Denial-of-service or load tests against production
- Issues in third-party projects linked from the portfolio unless they directly compromise this site
- Missing security headers or best-practice hardening without demonstrable impact
How to report
Email srujanchidarla.uof@gmail.com with subject line “Security vulnerability report”, or use the machine-readable contact in /.well-known/security.txt. Include:
- Description of the issue and potential impact
- Steps to reproduce (URLs, request samples, screenshots)
- Your assessment of severity (optional)
- Whether you want public credit (name/handle) after fix
Safe harbor
I will not pursue legal action against researchers who act in good faith: avoid privacy violations, data destruction, and service disruption; do not access data belonging to others; and give reasonable time to remediate before public disclosure.
Response timeline
- Acknowledgment — within 3 business days
- Initial assessment — within 10 business days
- Fix or mitigation — timeline depends on severity; critical issues prioritized
Recognition
With your permission, I may thank reporters in release notes or a security acknowledgments section. There is no paid bug bounty program at this time.
Preferred practices for researchers
- Use test accounts and minimal proof-of-concept data only
- Do not exfiltrate personal data from chat logs or server logs
- Report webhook or API key exposure immediately — do not use leaked credentials
Related policies
See also our Privacy Policy and Data Storage page for how user data is handled.