// Security
Security
Last updated: August 11, 2026
We take the security of elevenchase.com and the people who submit information through it seriously. If you believe you've found a security vulnerability, we want to hear about it.
Reporting a vulnerability
Email start@elevenchase.com with a description of the issue, the steps to reproduce it, and its potential impact. This address is monitored directly by the founder. A machine-readable version of this contact is also published at /.well-known/security.txt per RFC 9116.
Scope
In scope: elevenchase.com and its subdomains, including the contact and website-audit forms. This is a marketing website, not a product with user accounts or payment processing, so the realistic attack surface is limited to things like form-handling issues, header/transport misconfiguration, and dependency vulnerabilities.
Out of scope
Denial-of-service testing, automated scanning that generates significant traffic, social engineering or phishing against ElevenChase or its clients, and physical security are all out of scope. Please don't test in ways that could degrade the site for other visitors.
What to expect
We'll acknowledge a good-faith report as soon as possible, investigate, and follow up with what we found and any fix timeline. We won't pursue legal action against anyone who reports a vulnerability in good faith, avoids privacy violations and data destruction, and gives us a reasonable opportunity to fix the issue before disclosing it publicly. There is currently no paid bug bounty program.
Related pages
See our Privacy Policy for how information submitted through this site is handled.