HTTPS/TLS
Browser requests are sent over same-origin HTTPS. This protects transport against casual interception and redirect confusion.
Security
Mushku.com uses same-origin HTTPS routes for browser traffic. Please report vulnerabilities privately.
Browser requests are sent over same-origin HTTPS. This protects transport against casual interception and redirect confusion.
Transport security is not the same as encryption of encoded field payloads. Payload privacy claims are bounded separately.
Email security reports to sram@mushku.com with enough detail to reproduce the issue. The same contact is published at /.well-known/security.txt.
Please do not publicly post exploit details, private account data, live package material, or payment identifiers.
Reports about the website, package download path, account ledger behavior, same-origin API routes, and demo API are in scope.
Do not test paid-search abuse, Stripe abuse, account takeover, denial of service, or destructive behavior without written permission.
This is an early demo surface. Include impact, reproduction steps, affected URL or endpoint, and whether account or payment data was involved.