Security: if you find something, tell me.

This site makes real network connections on behalf of strangers, which is exactly the kind of thing that needs careful boundaries. Here is how to report a problem, and what is in place to prevent one. Last updated 2026-09-18.

Reporting a vulnerability

Email [email protected]. It reaches me directly. I read everything, I will acknowledge a genuine report, and I will tell you when it is fixed. There is no bug bounty; this is a free site run by one person. Credit in a fix note is yours if you want it.

The same details are published in the machine-readable security.txt (RFC 9116).

What to include

Please test against your own systems or ones you are entitled to test. Do not run denial-of-service tests against this site or use its tools to attack a third party; that is covered by the terms of use and it also does not tell either of us anything useful.

How the site handles data

The full description is on the privacy page. The security-relevant summary:

Protections that are actually in place

This list describes what the code does today. It is not a promise that nothing can go wrong, and it does not list things I have not built.

Things worth knowing before you report them

Scope

Everything served from kirkdiamond.com is in scope. Third-party services the tools talk to (public DNS resolvers, Team Cymru, RDAP servers, Google Fonts, the systems you point the tools at) are not mine and are out of scope; please report issues with those to their owners.

Privacy · Terms · About