Reporting a Vulnerability

If you discover a security vulnerability in x1y1.co or any X1Y1-operated system, please report it responsibly. We take all reports seriously and will respond promptly.

Email: security@x1y1.co

Please include as much detail as possible: the nature of the vulnerability, steps to reproduce it, and the potential impact. We will acknowledge your report within 48 hours and keep you informed as we investigate.

Responsible Disclosure

We ask that you:

  • Report vulnerabilities privately before disclosing them publicly
  • Give us a reasonable amount of time to investigate and remediate before any public disclosure
  • Avoid accessing, modifying, or deleting data that does not belong to you
  • Not perform actions that could degrade or disrupt the service

In return, we commit to:

  • Acknowledging your report promptly
  • Keeping you informed of our progress
  • Not pursuing legal action against researchers who act in good faith under this policy
  • Crediting you publicly for your finding, if you wish

Site Infrastructure Security

x1y1.co is served through Cloudflare's global network. Our security posture includes:

  • TLS everywhere: All traffic to x1y1.co is encrypted in transit using TLS 1.2 or higher.
  • DDoS protection: Cloudflare's network-layer and application-layer DDoS mitigation is active.
  • Bot protection: Contact form submissions are protected by Cloudflare Turnstile, a privacy-preserving challenge that does not use tracking cookies.
  • Serverless execution: Our application logic runs in Cloudflare Workers, which provides strong isolation between requests by design.
  • No persistent secrets in code: API keys and secrets are managed through Cloudflare's encrypted secrets store and are never committed to source control.
  • HTTPS enforced: HTTP requests are automatically redirected to HTTPS. HSTS is enabled with a long max-age.

Consulting Client Security

For clients engaging X1Y1 for engineering or AI consulting work, our security practices during engagements include:

  • Least-privilege access: we request only the permissions necessary for the scope of work
  • Credential hygiene: we use short-lived credentials where possible and rotate all access upon engagement completion
  • No data retention: client data and credentials are removed from our systems upon project conclusion
  • Secure communication: all sensitive project communication is conducted through encrypted channels

Contact

Security concerns: security@x1y1.co

General inquiries: hello@x1y1.co