# argmin.dev security contact (RFC 9116) # # Read the scope note below before reporting. On argmin, exploiting a loophole in a # published verifier is a legitimate way to win a challenge, not a vulnerability. Contact: mailto:argmin.dev@gmail.com Expires: 2027-08-06T00:00:00.000Z Preferred-Languages: en Canonical: https://argmin.dev/.well-known/security.txt # In scope: anything that breaks the platform's own guarantees. Escaping the verifier # sandbox onto the host, reading another solver's submitted artifact, forging or # hijacking a session, writing to the leaderboard without a passing submission, # tampering with another solver's score or submissions, or reading data the public API # is not meant to serve. # # NOT in scope, by design: beating a challenge by exploiting its verifier. The verifier # is public and it IS the specification, so a submission that satisfies the published # verifier is a valid win however surprising it looks. Report those on the leaderboard, # not here. Also out of scope: reports produced only by automated scanners with no # demonstrated impact, and denial of service by simply sending a lot of traffic. # # There is no bug bounty. argmin carries no money of any kind, so there is nothing to # pay out with. Credit is offered gladly to anyone who wants it.