Skip to content

Security Policy

How to report security vulnerabilities for ookyet.com and related identity infrastructure.

#Reporting a Vulnerability

If you find a security issue, report it by email:

  • ookyet.mid@gmail.com

For sensitive details, use the PGP key referenced in /.well-known/security.txt.

#Scope

In scope:

  • ookyet.com website security
  • ENS domain configuration for ookyet.eth
  • Identity verification integrations referenced on this site

Out of scope:

  • Third-party platform vulnerabilities (GitHub, X, Instagram, ENS app, etc.)
  • Social engineering requests
  • Physical security issues

#Disclosure Process

Please include:

  • Reproduction steps
  • Impact assessment
  • Suggested fix (optional)

Valid reports are reviewed and acknowledged as quickly as possible.