Security Policy

Responsible disclosure for https://portfolio.naciri.me

Contact

Email: izzyxnac@gmail.com (also listed in /.well-known/security.txt)

Expires: 2027-01-01T00:00:00.000Z

Scope

https://portfolio.naciri.me — static Next.js App Router portfolio behind nginx on Azure (20.250.161.13). No authentication, no uploads, no cookies. Security headers: HSTS (max-age=63072000; preload), X-Frame-Options: DENY, X-Content-Type-Options: nosniff, Referrer-Policy: strict-origin-when-cross-origin, Permissions-Policy (camera/mic/geo disabled), and per-request nonce CSP (script-src 'self' 'nonce-...' 'strict-dynamic').

Safe harbor

Good-faith research is welcomed. Do not exfiltrate, degrade, or access non-public data. Allow reasonable time to remediate before disclosure.

Out of scope

  • Clickjacking on static content (mitigated by frame-ancestors 'none')
  • Missing COOP/COEP/CORP — not needed for static portfolio

Canonical: https://portfolio.naciri.me/.well-known/security.txt · Hiring: /contact

Security Policy | Issam NACIRI Portfolio