Legal
Security
How to report something you have found, and what we run. If you think you have found a weakness, we want to hear it — and we will not come after you for looking.
Last updated 19 August 2026. Kaymen Group LLC.
Reporting something
Email elor@kaymengroup.com with what you found and how to reproduce it. A person reads it. We will confirm we received it, tell you what we think, and tell you when it is fixed.
Please give us a reasonable chance to fix it before publishing, do not access or change data that is not yours, and do not run tests that would take the site down or degrade it for other people.
What we will not do
If you report something in good faith and stay within the lines above, we will not pursue legal action against you and we will not report you. We will credit you if you want to be credited.
What is running here
Every request to this site passes through a filter that inspects the path, query, body and user agent for attack patterns, scores what it finds, and blocks addresses that cross a threshold. Blocks escalate with repeat offences and always expire.
Accounts lock after repeated failed sign-ins. Sign-in attempts are recorded. An unknown email address and a wrong password return the same error, deliberately, so the login cannot be used to discover who has an account.
That is the same shield we build into the systems we run for clients — this site is not a special case.
What we do not run
There is no bug bounty and no payment. This is a small company and the honest position is that we can offer thanks, credit and a fast fix, not money.