Security policy

Report via GitHub private vulnerability reporting or security@loremfile.dev. Acknowledgement within 7 days (the project has no on-call). No bounty. Please do not run volumetric tests against the service. In scope: anything that lets a third party change or remove content, execute script in the loremfile.dev origin, or inflate costs beyond the rate limit's intent. Out of scope: rate limiting itself, missing headers on 404 pages, findings that require a Cloudflare account compromise.