# Security — AWcode

_Security_

Who is responsible for security at AWcode and how to report a vulnerability.

## Security leadership

**Mark Walker, CEO**, is AWcode's security lead. He is accountable for the security of AWcode's own systems and of the websites, applications and servers we build and host for clients, covering server hardening, access control, patching and incident response.

Contact: <m@awcode.com>

## Reporting a vulnerability

If you believe you have found a security issue in an AWcode system or a site we host, email <m@awcode.com> with a description and the steps to reproduce it.

- We will acknowledge your report and keep you updated while we investigate and fix it.
- Please give us reasonable time to fix the issue before disclosing it publicly.
- Do not access, change or delete data that is not yours, and do not run tests that degrade service for others.

We will not pursue action against anyone who reports an issue in good faith and follows these guidelines.

---

**Canonical HTML version:** https://awcode.co.uk/security

**About this document:** This is a plain-Markdown mirror of an AWcode.com page, served so that LLMs and agents can read the content without executing the site's retro-OS JavaScript UI. The HTML page at the canonical URL above carries the same content and is also fully indexable.

## Machine-readable

Resources for AI agents, LLMs and integrations:

- [https://awcode.co.uk/llms.txt](https://awcode.co.uk/llms.txt) — index of markdown mirrors
- [https://awcode.co.uk/llms-full.txt](https://awcode.co.uk/llms-full.txt) — every page + post concatenated
- [https://awcode.co.uk/sitemap.xml](https://awcode.co.uk/sitemap.xml) — full sitemap
- [https://awcode.co.uk/robots.txt](https://awcode.co.uk/robots.txt) — crawl + Content-Signal policy
- [https://awcode.co.uk/ai.txt](https://awcode.co.uk/ai.txt) — AI access policy
- [https://awcode.co.uk/openapi.json](https://awcode.co.uk/openapi.json) — OpenAPI 3.1 spec
- [https://awcode.co.uk/.well-known/api-catalog](https://awcode.co.uk/.well-known/api-catalog) — RFC 9264 / 9727 link set
- [https://awcode.co.uk/.well-known/mcp.json](https://awcode.co.uk/.well-known/mcp.json) — MCP discovery
- [https://awcode.co.uk/mcp](https://awcode.co.uk/mcp) — MCP server endpoint (POST JSON-RPC 2.0)
- [https://awcode.co.uk/.well-known/agent-skills/index.json](https://awcode.co.uk/.well-known/agent-skills/index.json) — Agent Skills index

### Public API — concrete examples

- [GET https://awcode.co.uk/api/posts](https://awcode.co.uk/api/posts) — list recent published posts
- [GET https://awcode.co.uk/api/posts/how-startup-studios-de-risk-saas-builds-before-the-first-sprint](https://awcode.co.uk/api/posts/how-startup-studios-de-risk-saas-builds-before-the-first-sprint) — fetch one post
- [GET https://awcode.co.uk/api/pages/about](https://awcode.co.uk/api/pages/about) — fetch the about page

### Markdown mirrors — concrete examples

- [https://awcode.co.uk/index.md](https://awcode.co.uk/index.md) — homepage
- [https://awcode.co.uk/about.md](https://awcode.co.uk/about.md) — about page
- [https://awcode.co.uk/news/how-startup-studios-de-risk-saas-builds-before-the-first-sprint.md](https://awcode.co.uk/news/how-startup-studios-de-risk-saas-builds-before-the-first-sprint.md) — one news post
