What to include
- A concise description of the vulnerability and its potential impact.
- The affected URL, endpoint, component, or version.
- Reproduction steps or a minimal proof of concept.
- Relevant screenshots, logs, or request and response samples with secrets removed.
- Your preferred name and whether you want public credit.
Do not include active passwords, server secrets, service-role keys, session tokens, or unnecessary personal data in the first message.
Good-faith research rules
- Test only accounts and data you own or have explicit permission to use.
- Stop immediately if you encounter unrelated personal data, secrets, or access to another user’s workspace.
- Do not perform denial-of-service testing, spam, social engineering, physical attacks, or destructive actions.
- Use the minimum access needed to demonstrate the issue and do not retain collected data.
- Give us a reasonable opportunity to investigate and fix the issue before public disclosure.
- Follow applicable law and avoid privacy violations or service disruption.
Safe harbor
When research is conducted in good faith and in accordance with this policy, we will treat it as authorized security research and will not pursue legal action solely for accidental, limited violations caused by that research. This safe harbor does not apply to extortion, threats, data theft, disruption, intentional harm, or activity outside this policy.
Response process
Acknowledgement
We review incoming reports and confirm receipt when enough information is available.
Triage
We assess reproducibility, severity, affected components, and immediate risk.
Remediation
We work on a proportionate fix and may request validation or additional details.
Closure
We confirm resolution and coordinate disclosure or credit where appropriate.
Response and remediation times vary based on severity, complexity, and operational constraints. This policy does not promise a bounty or payment.
Out of scope
Examples include clickjacking on pages without sensitive actions, missing security headers without a demonstrated impact, self-XSS, brute-force reports without practical impact, denial-of-service testing, vulnerabilities only in unsupported third-party software, and issues requiring a victim to disable standard browser protections.