Security
Security
Report a security issue
Report a security issue
Preferred contact:
The machine-readable contact is also published at /.well-known/security.txt.
What to include
Include the affected URL or feature, concise reproduction steps, the likely impact, the date and time observed, and only the evidence needed to understand the issue. Do not send passwords, access tokens, or unrelated personal data in the initial report.
Responsible testing
Limit testing to your own accounts and data and use non-destructive checks. Do not access another person's data, impair availability, send high-volume automated traffic, use social engineering, retain unnecessary data, or disclose the issue publicly before a coordinated resolution.
What to expect
We aim to acknowledge a complete report within five business days and to provide status updates when practicable. This is a response target, not a promise of a reward or bounty.
Report data
Security reports and contact details are used only to assess, reproduce, and remediate the reported issue and to communicate with the reporter. They are kept only as long as reasonably required for security and legal purposes.