Skip to content

Security

A small public surface. A hard private boundary.

Security guidance for the public portfolio and its boundary with the private, single-user Personal OS. Last updated 1 August 2026.

Public surface

The pages, discovery documents, public profile API and public MCP server are intentionally unauthenticated. They expose professional portfolio information only. The MCP tools are read-only and declare their side-effect and idempotency properties.

Private surface

Personal OS pages and APIs require an authenticated, allow-listed owner account. Health, finance, investment, calendar, habit, goal, memory and Kai data are outside the public contracts. Public clients should treat a 401 or 403 response as a hard boundary and must not attempt to bypass it.

Responsible disclosure

If you believe you found a security issue, use the contact form and include the affected URL, impact and safe reproduction steps. Do not include credentials, access private data, degrade the service or publish an unresolved issue before there has been a reasonable opportunity to investigate.

Supported scope

Reports concerning darlington.dev and its first-party endpoints are in scope. Social profiles, linked third-party projects and external providers are governed by their own security policies. This is a personal project, not a paid bug-bounty programme.