Security
Report a potential vulnerability.
We welcome good-faith reports that help us protect this website and the people who use it.
What to include
Describe the issue, where you found it, the potential impact and the smallest set of steps needed to reproduce it. Screenshots or non-sensitive proof may help us investigate.
Good-faith testing
Use only accounts and data you own or have explicit permission to test. Stop if you encounter personal information, credentials or evidence of active compromise, and report it promptly.
Please do not
Do not disrupt service, access or change another person’s data, use social engineering, send malware, run denial-of-service tests, perform high-volume automated scanning or publicly disclose an unresolved issue.
What to expect
We aim to acknowledge a report within three business days. We will assess reproducibility and impact, keep you informed when practical and coordinate disclosure timing where a valid issue needs remediation.
Coordinated disclosure
Please give us a reasonable opportunity to investigate and address a valid issue before publishing details. Any recognition or public disclosure will be agreed with the reporter and will not expose affected people or systems.
