DEAD HAND
Dead Hand  /  Security

Security

Your rates and your job history are the private numbers of your business. Here is how they are kept, and how to tell us if something looks wrong.

Reporting something

If you think you have found a vulnerability, email [email protected] and put SECURITY in the subject line.

Tell us what you found and how to reproduce it. You will get a reply from a person, usually within two business days. We will not send you a lawyer for reporting a real problem in good faith, and we will tell you when it is fixed.

The machine-readable version of this is at /.well-known/security.txt.

How it is built

Dead Hand is a small web app with a deliberately short list of moving parts. Fewer pieces is itself a security decision.

What we do not hold

The shortest way to keep something safe is to not have it. Dead Hand holds no card numbers, no bank details, no tax information, no location history, no contacts, no photos, and no customer email addresses. When you send an estimate it goes out through your own mail app, so the recipient's address never reaches us.

What we do hold is set out in full on the privacy page.

The honest part

This is a one-person operation, not a company with a security department. That cuts both ways. There is nobody to hide behind if something goes wrong, and there is also nobody to lose your report in a queue. If something is broken, the person who wrote it will read your email.

We do not run a paid bug bounty. If you find something real, we will fix it, credit you if you want the credit, and say thank you properly.

If something happens

If shop data is ever exposed, we will email everyone affected with what happened, what was in it, and what we did about it — without waiting to be asked, and without the word "unauthorized third party" doing all the work.