Security

Security Policy & Coordinated Disclosure

If you believe you have found a security issue affecting spicemodo.com, please report it to us privately. We appreciate the research community and commit to acting on reports quickly and in good faith.

Effective: 17 April 2026 Last reviewed: 17 April 2026 Next review: 17 April 2027 Machine-readable: /.well-known/security.txt

1. Scope

This policy covers security issues in the assets we publish and operate directly:

Out of scope

2. How to Report

Send a single email describing the issue to [email protected]. Please include:

Please do not: publish the issue before we have had a chance to respond, send bulk marketing or phishing-style emails, or use automated scanners that generate high volumes of traffic against our origin. If you need to disclose urgently because users are at active risk, say so in the subject line.

3. Our Commitments (SLA)

4. Safe Harbor

When a researcher complies with this policy, acts in good faith, and avoids harming users or data, SpiceModo:

We cannot, and do not, grant safe harbor for activity that breaks the law or harms third parties. If a legal issue arises, please contact us first so we can help clarify scope before escalation.

5. Rules of Engagement

6. What We Do Not Pay

SpiceModo does not currently operate a paid bug-bounty programme. We offer public credit and, for notable reports, a small thank-you (such as a pack of our flagship spices). We reserve the right to introduce a bounty programme in the future.

7. Languages

Reports are accepted in English. Our team is based in Hyderabad, India (IST / UTC+05:30); responses typically arrive within business hours.

8. Public Key & Encryption

A PGP key for encrypted reports will be published at /.well-known/pgp-key.txt in a future update. Until then, please reach out at [email protected] and we will coordinate an out-of-band channel if the report is sensitive.

9. Changes

This policy may be updated to reflect operational changes. Material changes will bump the "Last reviewed" date above. The machine-readable companion at /.well-known/security.txt follows RFC 9116 and is kept in sync.

Contact