Security Policy

Scope: lawndart.dev and tools.lawndart.dev

Developer: Lawn Dart Systems, LLC

Effective Date: August 11, 2026

Last Updated: August 11, 2026

Reporting a vulnerability

If you believe you have found a security vulnerability in a system covered below, email security@lawndart.dev. Please include enough detail to reproduce the issue — the affected URL or endpoint, the steps you took, and what you observed.

A machine-readable version of this policy is published at /.well-known/security.txt.

What is in scope

  • lawndart.dev — this site, including its contact and chat endpoints
  • tools.lawndart.dev — the free Business Tools

What is out of scope

These are excluded because they are not mine to authorize testing on, or because a report belongs with the vendor who operates them:

  • Client-owned systems. Systems I administer on a client’s behalf belong to that client. I cannot grant permission to test them, and I will not act on a report that required unauthorized access to produce.
  • Third-party services. Google, Anthropic, Resend, Firebase, and other providers run their own disclosure programs. Report issues in their platforms to them.
  • Other Lawn Dart! properties not listed above, including slotd.app, which is a separate product with its own surface.
  • Findings from automated scanners with no demonstrated impact, missing headers or best-practice recommendations with no exploitable consequence, denial of service, social engineering, and physical attacks.

What I commit to

I acknowledge reports within three business days. Lawn Dart Systems is a one-person firm, so that is an acknowledgement commitment, not a remediation deadline — I would rather state a number I can keep than one that reads well.

After acknowledging, I will tell you whether I consider the issue valid and in scope, keep you informed while it is being addressed, and credit you when it is resolved if you would like to be credited. There is no bug bounty; I cannot offer payment.

Safe harbor

I will not pursue legal action against you for security research conducted in good faith under this policy — that is, research that stays within the scope above, stops at the point where a vulnerability is demonstrated, and does not access, modify, destroy, or retain data that is not yours.

Please give me a reasonable opportunity to address the issue before disclosing it publicly, and do not use a finding to degrade service for anyone else. This safe harbor covers me only. It cannot bind a client, a hosting provider, or any third party.

The prohibition on probing this site in our Terms of Service does not apply to research conducted under this policy — that is the responsible-disclosure process it refers to.

Contact

security@lawndart.dev

Lawn Dart Systems, LLC — Floresville, TX · Disabled Veteran Owned
LegalPrivacyTerms© 2026 Lawn Dart Systems, LLC