Updated 19 September 2026
Report a security vulnerability
Send a private, reproducible report while protecting other users and avoiding unnecessary exposure.
Where to report
Report a suspected AntiCode security vulnerability to security@anticode.app with the subject AntiCode security report. AntiCode is operated by Rashad Elkersawy. Start with a concise description and a safe way to reproduce the issue. Do not send live credentials or unnecessary customer information by email. If sensitive evidence is essential, first ask how to share it appropriately.
What to include
Identify the affected page, component, or release, the access required, what you did, what happened, and the security impact you believe follows. Use synthetic accounts and data wherever possible. Redacted screenshots or a minimal non-destructive proof of concept can help explain the issue without exposing someone else's information.
Testing boundaries
This policy is an invitation to report, not blanket permission to test the live service. Test only systems and accounts you control or are explicitly authorised to test. GitHub, OpenAI, Supabase, Cloudflare, and other providers are outside any testing permission AntiCode could grant for its own application.
Do not disrupt availability, send abusive traffic, attempt social engineering, retain unauthorised access, or retrieve other customers' information. If private information becomes visible unexpectedly, stop, avoid making additional copies, and explain the circumstances in your report.
Coordination
Please contact us before publishing technical details that could expose users while an issue is being assessed. We may ask for clarification or a safer reproduction. A response time, bounty programme, or legal safe-harbour commitment is not currently offered.
If you follow up, include your original report and avoid resending sensitive evidence unnecessarily. A missing acknowledgement does not grant permission for additional testing. Ordinary product support and privacy requests can also be sent to security@anticode.app.
Contact fallback
If you cannot reach security@anticode.app, email admin@rtwochain.com and identify AntiCode in the subject.