Report a security vulnerability

Email [email protected] with affected URL/component, impact, reproducible steps and minimal evidence. Do not access other users' data, use social engineering, degrade service, run destructive tests, retain data or publicly disclose before a reasonable remediation period.

Good-faith research following this policy will be treated as authorized to the extent we can do so. We will acknowledge, triage, communicate and credit researchers when desired. This is not a promise of payment and does not authorize testing third-party providers.