Responsible disclosure
If you find a vulnerability in www.aststracker.space or api.aststracker.space, please report it privately so we can fix it before public disclosure.
- Email: ciber@me.lisaso.es
- Author / profile: pablolisaso.com
- Machine-readable contact: security.txt
Please include steps to reproduce, impact, and (if possible) a suggested fix. We aim to acknowledge reports within a few business days.
Scope
- In scope: https://www.aststracker.space and https://api.aststracker.space
- Out of scope: third-party services we call (CelesTrak, Space-Track, CDNs, email provider), social engineering, DoS only, or physical security
Controls we apply
- HTTPS with HSTS (preload-oriented max-age)
- Content-Security-Policy, frame denial, nosniff, Referrer-Policy, Permissions-Policy
- Rate limiting on the API host (per IP, stricter on refresh)
- No cookies / sessions for the public tracker UI
- Secrets (Resend, Space-Track) stored as Worker secrets, not in git
- Public API is read-oriented; write-heavy pulls are throttled
Check header grade on securityheaders.com.
Acknowledgments
We appreciate good-faith security research. With permission, we may thank reporters on this page.
Not affiliated
BlueBird Tracker is an independent project by Pablo Lisaso. Not affiliated with AST SpaceMobile.