Report a security issue
A responsible way to tell us about vulnerabilities.
Disclosure principles
We welcome genuine security research and handle reports confidentially. We appreciate: reports that include enough detail to reproduce the issue; no loud public disclosure before we have fixed it; and a reasonable window for us to respond. Reports are handled in a read-only, non-destructive spirit.
What to include
Use the contact form and choose "Security" as the topic. Give us your name (or handle) and email; a clear description of the vulnerability; the affected URL; steps to reproduce, step by step; the expected versus actual impact; and, if helpful, a small attachment such as a screenshot. Never include live sensitive data.
What happens next
We triage, fix and, where it matters, notify affected users. We do not publish security reports or researcher identities without consent. Out-of-scope or already-known issues may not get a dedicated reply.
What is out of scope
Social engineering, denial-of-service, physical intrusion, and issues with third-party services we do not control are outside this program.
Good faith
Researchers acting in good faith per this page will not be penalised for their work.
Questions about this policy? Contact us.