ElCampeon Systems

Trust

Found a flaw? Tell us.

We break things for a living, so we expect people to try our work too. If you find a vulnerability in our site or apps, we want to hear about it.

Last updated 8 October 2026

Report to tanmay@elcampeon.dev with the subject "Security report". Our security.txt lists the same contact.

How to report

Please include:

  • The app or URL affected, and its version if it's an app.
  • Step-by-step instructions to reproduce the issue, with requests or screenshots.
  • What an attacker could do with it.
  • Whether you'd like to be credited, and how.

English, Hindi or Marathi are all fine.

Scope

In scope:

  • This website, elcampeon.dev.
  • Our Android apps on Google Play: Learn Web Application Security, Learn Algorithms & DS, and BMI Calculator.
  • The server our apps will use to reach the Claude API, once it's live.

Out of scope:

  • Services run by other companies, including Google Play, Cloudflare and Anthropic. Report those to them directly.
  • Denial of service, spam, social engineering and physical attacks.
  • Findings from automated scanners without a demonstrated impact.
  • Missing best-practice headers or settings with no exploitable effect.

Testing rules

  • Only access or change data that belongs to you. Stop and report as soon as you see anyone else's.
  • Don't degrade the service for other people.
  • Give us reasonable time to fix the issue before you share it publicly.

What we commit to

  • We'll acknowledge your report within two working days.
  • We'll keep you updated while we investigate and fix it.
  • We'll credit you when it's fixed, if you'd like that.

We're a small company and don't run a paid bug bounty yet.

Safe harbor

If you follow this policy in good faith, we consider your research authorized, won't pursue legal action against you for it, and will say so if anyone else asks.