Security Policy
Responsible disclosure for https://portfolio.naciri.me
Contact
Email: izzyxnac@gmail.com (also listed in /.well-known/security.txt)
Expires: 2027-01-01T00:00:00.000Z
Scope
https://portfolio.naciri.me — static Next.js App Router portfolio behind nginx on Azure (20.250.161.13). No authentication, no uploads, no cookies. Security headers: HSTS (max-age=63072000; preload), X-Frame-Options: DENY, X-Content-Type-Options: nosniff, Referrer-Policy: strict-origin-when-cross-origin, Permissions-Policy (camera/mic/geo disabled), and per-request nonce CSP (script-src 'self' 'nonce-...' 'strict-dynamic').
Safe harbor
Good-faith research is welcomed. Do not exfiltrate, degrade, or access non-public data. Allow reasonable time to remediate before disclosure.
Out of scope
- Clickjacking on static content (mitigated by
frame-ancestors 'none') - Missing
COOP/COEP/CORP— not needed for static portfolio
Canonical: https://portfolio.naciri.me/.well-known/security.txt · Hiring: /contact