Trust & legal

Security & responsible disclosure

If you have found a weakness in this website, we would much rather hear it from you than discover it later. This page explains how to report it and what you can expect.

Effective 3 October 2026All policies

How the site is protected

  • All pages are served over HTTPS, and plain HTTP requests are redirected.
  • The site is static: there are no user accounts, no logins and no database behind the pages.
  • Form submissions are validated, rate limited and stored outside the publicly accessible part of the server.
  • Pages load no third-party code, which removes a common route for compromise.

Reporting a vulnerability

Send a report through the contact form and begin your message with the word "Security". Please include:

  • the address of the affected page or endpoint;
  • what the issue is and why it matters;
  • the steps needed to reproduce it; and
  • how to reach you if we have questions.

Please do not include passwords, personal data belonging to other people, or large attachments in the first message.

In scope

The website at perigonmedia.com and www.perigonmedia.com, including its form endpoints.

Out of scope

  • Third-party platforms and services, including our hosting provider's own infrastructure. Report those to the provider.
  • Client websites, advertising accounts and campaigns.
  • Denial-of-service testing, volumetric attacks and automated scanning that degrades the site.
  • Social engineering of our staff, clients or partners, and physical attacks.
  • Reports generated by automated tools without a demonstrated impact, such as missing optional headers.

Good-faith research

If you make a good-faith effort to follow this page, we will treat your research as authorized, will not pursue legal action against you for it, and will work with you to understand and resolve the issue. Good faith means that you:

  • test only what is in scope;
  • stop and report as soon as you confirm a vulnerability, without using it to view, change or remove data;
  • do not disrupt the site for other visitors; and
  • give us reasonable time to fix the issue before telling anyone else.

What to expect

We will acknowledge your report, tell you whether we can reproduce it, and let you know when it is fixed. We do not run a paid bug bounty. With your permission we are glad to credit you by name once the issue is resolved.

Machine-readable contact

A security.txt file pointing to this page is published at the standard location.