Found something? Tell us.
If you have found a security issue in this website or in Atarla software, Atarla wants to hear about it before anyone else does. Reports are welcome from anyone, including people who found the issue by accident.
How to report.
Use the contact form and choose Other as the reason, or read /.well-known/security.txt for the current machine-readable contact details. Include what you did, what you saw, and roughly when.
Please do not run automated scans against production, access data that is not yours, or degrade the service for other people while testing.
What to expect.
Atarla is a solo-founder company, so there is no security operations team and no guaranteed response window. A report will be read by a person and acknowledged.
There is no bug bounty. Atarla will credit reporters who want credit, and will not pursue anyone who reports a genuine issue in good faith.
What this website does.
- The site is a static build served from Cloudflare, with a narrow worker handling form endpoints only.
- Form submissions are same-origin checked, size and field validated, honeypotted, rate limited, and written with prepared statements. There is no public read endpoint.
- No third-party analytics or advertising scripts. Fonts and images are served from this origin.
- Security headers and a machine-readable security.txt are published with the site.
What is not claimed.
No system is free of risk. Atarla holds no security certification, has not been audited by a third party, and does not claim that a report will be resolved within any particular time.