Skip to main content

Contact

How to reach us, and what we can’t take yet

One address on this page is monitored. The rest of it is an honest account of the things this site cannot do for you today, so you don’t spend an afternoon waiting on a reply that was never going to come.

What works right now

Security vulnerability
Email security@ourelectedportfolios.com
Open
Correction to a filing
The figures on this site are drawn from real US House filings now, so a correction is a real thing to report — but no address takes one yet
No route
Press, feedback, anything else
No general address is configured, and there is no public issue tracker
No route
Your account or your data
Optional accounts exist, but no dedicated privacy or support inbox is configured; use the security address for a privacy request and do not include unnecessary sensitive information
Security inbox only

Security reports

If you have found a flaw in this site — a way to read or write something you shouldn’t, an exposed credential, an injection, a broken authorization check — send it to security@ourelectedportfolios.com. That address is published at /.well-known/security.txt in the RFC 9116 format, and it is the only address this project monitors.

A report is easiest to act on when it carries:

  • the URL or endpoint, and the exact request you sent
  • what you expected to happen, and what happened instead
  • enough detail for someone else to reproduce it once
  • whether you have disclosed it elsewhere, and any deadline you are working to

Please don’t test against anyone else’s data, and don’t run load or denial-of-service testing against the site. There is no bug bounty and no payment for security research. The single Supporter plan funds product workflows, not a bounty program, so reporting is voluntary and treated as a favour to the people who use the record. The security.txt file lists no encryption key, so until it does, treat plain email as plain email.

Corrections to filing data

There is now something to correct, and still no route to report it on. That gap is ours rather than yours, and this is what stands behind it. The figures here come from periodic transaction reports filed with the Office of the Clerk of the House. The live disclosure catalog is the authority for document, readable-report, image-only and transaction totals; repeating those changing measurements on a contact page made this copy stale. Newer House years are published only after the same coverage checks pass. Nothing from the Senate is published.

When a correction route opens it is published in this section, and two things will be true of it. A correction needs to name the filing and the field, because that is what makes it checkable against the source document — every indexed filing, readable or not, appears in the disclosure catalog with its House Clerk source link. And where the disclosure itself is wrong, the amendment is filed with the House Clerk, not with us: this site reports what was filed. It is not the record, and it cannot change one.

Two things that will never be a correction. We preserve the amount exactly as filed: the standard form uses a dollar range, while rare amendments can state an exact value. And 35 transactions carry a notification date earlier than the trade date they report. Those are the filers’ own slips, kept as filed rather than tidied up, because a database that silently repairs a public record stops being a copy of it.

Press, questions, everything else

There is no general contact address. Not a slow one — none. Press enquiries, feature requests, data questions and “is this thing on?” all have no route today, and the repository is private, so there is no public issue tracker to file to either.

The security address is not a substitute for one. It is monitored for vulnerability reports, and a queue full of general mail is how a real report gets read three weeks late. When a general address exists it will be listed in this section — and the fact that this paragraph is still here is how you will know it doesn’t.

Account and newsletter requests

Account and newsletter data have self-service routes: account settings cover account lifecycle, and every newsletter edition must carry an unsubscribe link. Ordinary public research pages load no third-party analytics tag and set no application account or analytics cookie. Optional first-party measurement, when enabled, stores only anonymous daily categories with no reader profile and exposes its in-app totals only to a Super Admin; a configured newsletter form loads the hCaptcha abuse check disclosed in the privacy notice. The server does not read a session simply because you view a public page. Supporter billing is managed from the signed-in billing page and Stripe customer portal. The hosting provider also keeps an ordinary request log, which records your IP address the way every web server does, and a browser Content-Security-Policy violation can post a truncated report to the same log. The account, newsletter and log boundaries are described in full on the privacy page.

Free public pages may carry carefully approved advertising. Signed-in Supporters are ad-free, and entitlement uncertainty disables the ad request. Any material change to that boundary will be written here before it is discovered afterwards.

Who this is not

Our Elected Portfolios is an independent project. It is not affiliated with, endorsed by, or speaking for the House of Representatives, the Senate, any member of Congress, any committee, or any other government body, and it cannot help with anything addressed to one of them. The filings its figures are drawn from are public records held by the Office of the Clerk of the House; that office is the place to go for the documents themselves.

Nothing published here is investment advice, and no one here is licensed to give any.