Skip to content
Farid Mahmudlu
  1. 01 Process
  2. 02 Work
  3. 03 Log
  4. 04 Contact
  • EN — English
  • AZ — Azərbaycanca
  • HU — Magyar
Farid Mahmudlu
  1. 01 Process
  2. 02 Work
  3. 03 Log
  4. 04 Contact
  • EN — English
  • AZ — Azərbaycanca
  • HU — Magyar
  1. Farid Mahmudlu
  2. Security policy

Legal

Security policy

Last updated: October 5, 2026

On this page

  1. Reporting a vulnerability
  2. Scope
  3. Safe harbour
  4. What to expect
  5. How this website is hardened
  • Privacy policy
  • Legal notice
  • Terms of use
  • Accessibility

Reporting a vulnerability

If you believe you have found a security issue on this website, please email me with the subject line “Security”. Include a description of the issue, the steps to reproduce it, its potential impact and, if possible, a proof of concept. Please do not include other people’s personal data.

A machine-readable contact file is published at /.well-known/security.txt in line with RFC 9116.

Scope

In scope: the website at faridmahmudlu.dev, including its HTTP response headers and configuration.

Out of scope:

  • third-party services such as Cloudflare, GitHub, LinkedIn or Google — please report to them directly;
  • the products listed in the portfolio — please contact their teams (if you are unsure, email me and I will forward your report);
  • denial-of-service or volumetric testing, spam and social engineering;
  • reports from automated scanners without a demonstrated impact;
  • missing best-practice headers or settings without a practical exploit.

Safe harbour

If you act in good faith and follow this policy, I will consider your research authorised and will not pursue legal action. Please:

  • access only the minimum data needed to demonstrate the issue;
  • avoid degrading the website for other visitors;
  • give me reasonable time to fix the issue — normally 90 days — before disclosing it publicly.

What to expect

I aim to acknowledge reports within five business days and to keep you informed until the issue is resolved. With your permission, I will gladly credit you. This is a personal website, so there is no paid bug bounty.

How this website is hardened

  • Static by design: no server-side code, database, forms or user accounts.
  • Strict Content Security Policy: no inline scripts or styles, no eval, Trusted Types enforced, framing disabled.
  • Transport security: HTTPS only, HSTS with preload; the .dev top-level domain is itself HSTS-preloaded.
  • Isolation headers: Cross-Origin-Opener-Policy, Cross-Origin-Resource-Policy, X-Content-Type-Options and a restrictive Permissions-Policy.
  • Minimal third parties: fonts and scripts are self-hosted; the only external script is Cloudflare’s cookieless analytics beacon.
  • Supply chain: dependencies are pinned to exact versions, and new releases are installed only after a seven-day waiting period.
  • Privacy: no cookies of its own, and the email address is never published in plain text in the HTML.
Contact Farid Mahmudlu · Budapest, HU Email: hello [at] faridmahmudlu [dot] dev

Back to the homepage

Farid Mahmudlu

Full-Stack & AI Software Developer · Budapest, Hungary

No cookies. No ad trackers. No fingerprinting.

Legal

  • Privacy policy
  • Legal notice
  • Terms of use
  • Accessibility
  • Security

Elsewhere

  • GitHub (opens in a new tab)
  • LinkedIn (opens in a new tab)
  • Back to top

© 2026 Farid Mahmudlu. All rights reserved.