Security fixes are made on main and deployed to roughlogic.com. Older forks,
downloaded copies, and third-party deployments are not maintained by this
project.
Do not open a public issue for a suspected vulnerability. Email
hi@claygood.com with the affected URL or file, the impact, and minimal
reproduction steps. Do not send passwords, API tokens, private keys, personal
information, or data taken from another person.
Reports are acknowledged as quickly as practical. Credible issues that affect the live site are targeted for review within 72 hours, with 12-24 hours preferred for issues that could expose data, bypass abuse controls, or change a calculator result.
The static website, calculator-report Worker and D1 path, build and deployment configuration, and local read-only MCP server are in scope. Calculator formula or result problems should use the calculator's Report a problem button instead of this security channel.