Security
Security Policy
Effective September 1, 2026.
Applies to: https://potomactech.net and its subdomains, operated by Potomac Technologies, LLC.
Our commitment
Potomac Technologies, LLC takes the security of potomactech.net seriously. We appreciate the efforts of security researchers who help us identify and fix vulnerabilities responsibly. This policy explains how to report a security issue and what you can expect from us in return.
Scope
In scope:
- https://potomactech.net and any first-party subdomains (e.g.
*.potomactech.net) - The Astro-based site and its Cloudflare-hosted infrastructure, to the extent misconfigurations are reachable from the public site
Out of scope:
- Websites we host or maintain on behalf of our clients. We host and provide care plans for sites on other domains. Those are our clients’ property, and this policy does not authorize testing against them. If you believe you have found an issue affecting a site we operate for someone else, please report it to us using the details below and we will coordinate with the site owner — but do not test it further.
- Third-party services we link to or embed but don’t control (social media platforms, analytics providers, our DNS registrar, Cloudflare’s own platform-level infrastructure) — please report those directly to the relevant provider
- Denial-of-service, volumetric, or resource-exhaustion testing
- Social engineering, phishing, or physical attacks against Potomac Technologies personnel or facilities
- Automated scanning that generates significant traffic without prior coordination
- Findings that require physical access to a user’s device
- Reports based solely on missing “best practice” headers or configurations with no demonstrated impact
How to report
Email security@potomactech.net with:
- A description of the vulnerability and its potential impact
- Steps to reproduce, including any proof-of-concept, screenshots, or requests
- The URL(s) or component(s) affected
- Your contact information, if you’d like to be credited or kept in the loop
If your report involves sensitive details, you can encrypt it using our public PGP key.
Please do not include third-party personal data in your report. If demonstrating an issue required you to view any, describe what you saw rather than attaching it.
Safe harbor
If you make a good faith effort to comply with this policy while researching and reporting a vulnerability:
- We will not pursue legal action against you or refer you to law enforcement for that research
- We consider your research authorized under applicable anti-hacking laws (e.g. the Computer Fraud and Abuse Act), and exempt from any restriction in our Terms and Conditions that would otherwise prohibit it, to the extent necessary to carry out the research described here
This safe harbor covers only systems listed as in scope above. We cannot grant authorization to test systems belonging to our clients or to third parties.
In return, we ask that you:
- Give us reasonable time to investigate and remediate an issue before disclosing it publicly
- Avoid accessing, modifying, or exfiltrating data beyond what’s necessary to demonstrate the issue
- Stop testing and notify us immediately if you encounter personal data, credentials, or other sensitive information that isn’t yours
- Only interact with accounts or data you own, or have explicit permission to test
What to expect from us
- Acknowledgment of your report within 5 business days
- An initial assessment of severity and next steps within 10 business days
- Ongoing updates as we work toward a fix, and notice once it’s resolved
- Credit in a public acknowledgments note or release notes, if you’d like it — we don’t currently run a paid bug bounty program
Thank you for helping keep potomactech.net secure.