Reporting abuse and security problems
Two addresses, both monitored. Use whichever fits, and if you are unsure, pick either and we will route it.
Report an abusive app
Phishing, malware, impersonation, or content that should not be hosted: email abuse@homespun.dev.
Include the full address of the app, what it is doing, and a screenshot if you have one. We can take an app offline without needing anything from its owner.
Report a security vulnerability
A flaw in Homespun itself, rather than in something someone built on it: email security@homespun.dev.
Please report privately and give us a chance to ship a fix before you publish. Send a description, the steps to reproduce it, and which part is affected (the relay, the CLI, the SDK, or the MCP server).
What happens next
- We acknowledge your report within 3 business days.
- You get an initial assessment within roughly a week.
- We keep you updated while a fix is built, and credit you when it ships if you want that.
Homespun is a small pre-1.0 project, so these are honest targets rather than a contractual SLA.
Apps built by other people
Apps are published by the people who build them, each on its own subdomain of homespunapps.com. Homespun hosts them; it does not review or endorse their content.
That domain carries its own contact addresses, so a report about a single app can go straight to abuse@homespunapps.com. Reaching us at either domain works; both arrive in the same place.
Machine-readable
The same contacts are published at /.well-known/security.txt, following RFC 9116.