Vulnerability disclosure
Help us keep our services secure. How to report the vulnerabilities you find, responsibly.
Effective date:
How to report
Email your findings to our security address below. Please give us reasonable time to fix the issue before disclosing it publicly.
What to include
- The affected address, page or endpoint
- A short description of the vulnerability and its possible impact
- Step-by-step instructions to reproduce it
- A screenshot or sample request, if you have one
Our commitments
- We confirm receipt of your report as soon as we can.
- We keep you informed while we assess and fix the issue.
- We will not take legal action against good-faith research that follows this policy.
Research rules
- Test only with accounts and data that belong to you.
- Don’t access, change or delete other people’s data.
- Avoid tests that disrupt the service (load testing, denial of service).
- Social engineering and physical attacks are out of scope.