Responsible Disclosure Policy

We take the security of our systems seriously and value the work of the security community. If you believe you've found a vulnerability, we'd like to hear from you.

Reporting a vulnerability

Email us at [email protected]. To help us respond quickly, please include:

  • A clear description of the issue and its potential impact.
  • Steps to reproduce it (affected URL, request, or proof of concept).
  • Your name or handle, if you'd like to be credited.

What you can expect from us

  • We will acknowledge your report within 5 business days.
  • We will keep you informed as we investigate and work on a fix.
  • We will not take legal action against you for security research conducted in good faith and in line with this policy.
  • With your permission, we're happy to credit you on our acknowledgements page once the issue is resolved.

Guidelines

When researching, please:

  • Only test against your own accounts and data — never access, modify, or delete data belonging to others.
  • Avoid actions that could harm the reliability of our services (no denial-of-service, no automated high-volume scanning).
  • Do not use social engineering, phishing, or physical attacks against our staff or infrastructure.
  • Give us a reasonable time to resolve the issue (typically 90 days) before disclosing it publicly.

Out of scope

The following generally do not qualify:

  • Reports from automated scanners without a demonstrated, exploitable impact.
  • Missing best-practice email configuration (SPF, DKIM, DMARC) with no real-world exploit.
  • Clickjacking on pages without sensitive actions, or self-XSS.
  • Vulnerabilities in third-party services we don't control.

Recognition

With your consent, we list researchers who have responsibly disclosed valid issues on our acknowledgements page.