If you've found a way to break something in a way that puts data or money at risk, we want to hear it from you first — and we'll work with you, not against you.
Use the report form with the security box ticked, or email bugs@domainless.fun. Both land with the same two people. Reports marked as security are held private permanently — they can't be published from our own tools, and they never appear on the status page.
Please include enough for us to reproduce it: what you did, what you saw, and which part of the platform. If you have a proof of concept, describe it rather than running it against other people's accounts.
If you follow this page in good faith, we will treat your research as authorised. We won't bring a claim against you, we won't ask anyone else to, and if a third party comes after you over research that stayed within these rules, we'll make it clear publicly that you had our permission. If you're unsure whether something is in scope, ask first — we'd much rather answer a question than receive an apology.
This is a promise about how we'll behave. It isn't legal advice, and it can't bind anyone but us.
In scope: domainless.fun and its apps, jandgstudios.fun, and our mail infrastructure at mail.domainless.fun.
Out of scope, because they aren't ours to authorise or aren't defects we can act on:
We don't run a paid bounty programme. We're a two-person studio and we'd rather promise something we can keep than advertise a reward we can't. What you get is a fast human response, honest updates, public credit if you want it, and our word on the safe harbour above.
Ordinary bugs — things that are broken, ugly, or confusing — go to the bug report form. Those are just as welcome; they're simply handled in the open rather than under embargo.