Security
Report a problem
Found a vulnerability in this site or in the code of one of its projects? Please write to support@houjun.dev with the subject “Houjun Lab security” before telling anyone else, and do not open a public issue for it. Say what you found, how to reproduce it and, for code, which version (commit) you used. We will acknowledge your report, keep you informed, and credit you when it is fixed if you wish. There is no bug bounty.
Machine-readable contact: security.txt; this page is the policy it points to.
This website
- Static pages only. No scripts run on any page, nothing is loaded from third parties, and there are no forms, logins or cookies.
- Strict browser rules. Every page is served over HTTPS with a content security policy that forbids scripts, plus HSTS, no-sniff and framing protections.
- Read-only. The server accepts only page requests (GET and HEAD); anything else is refused.
- Nothing private is served. Notes, data files, code, archives, model weights and hidden files are refused even if one were uploaded by mistake, and folders cannot be listed.
The research code
Project code is published only after a check that no data, model weights, local paths or private notes are included. Data and models are downloaded from their publishers at pinned versions and verified by checksum.
Last updated 2 October 2026.