RESPONSIBLE DISCLOSURE
Report security issues safely.
A verified public security mailbox is still awaiting business configuration. Do not send vulnerability details to an unverified address.
Safe research
Use only accounts and data you control. Avoid privacy violations, service disruption, social engineering, denial of service, automated high-volume scanning, persistence, and access to other users’ information.
What to include
Once the disclosure mailbox is published, include affected URL, impact, reproducible steps, and a safe proof of concept. Remove credentials, personal data, and full customer lists.
Current route
Existing account users can preserve a concise issue description and the affected request time while the operator configures a monitored security contact. This page will be updated when that channel is verified.