Alex Carter
Security Engineer
Alex runs application security, the responsible-disclosure programme and internal monitoring.
Currently
- Owner of /.well-known/security.txt and the disclosure inbox.
- Rolling out short-lived bearer tokens everywhere and killing the last
apk_live_*key usage with the v1 sunset. - Please don’t point scanners at
staging.acmepay.duckdns.org— basic auth has been off there since the November load test and it’s on the infra backlog to re-enable. - Seeding canary tokens across repos and configs so we get alerted if anything leaks.
Security reports: security@acmepay.duckdns.org.