Security at Yetty

We care about the safety of the people who build and run their sites on Yetty. If you have found a security problem, thank you - we want to hear from you.

How to report

Email [email protected] with what you found and where, how to reproduce it, and what an attacker could do with it. If the details are sensitive, say so on the first line and we will arrange a private channel first. We aim to acknowledge within 12 hours.

Good-faith research

Use only test accounts you control; do not access, change, or delete other people's data; stop once you have proven the issue; and give us a reasonable window to fix it before disclosing publicly.

We will not pursue legal action against anyone who reports a vulnerability in good faith, follows this policy, and acts to avoid privacy violations and service disruption. We do not run a paid bounty today; our thanks are public credit and a genuine, timely fix.

Security thanks

With their permission, we credit the people who have helped us keep Yetty safe:

Researchers may ask us to use a handle instead of their name, or to stay anonymous - just tell us.

Machine-readable policy: /.well-known/security.txt (RFC 9116).