We welcome reports from security researchers. This page describes our scope, expectations, and safe-harbor commitment.
Email [email protected] with details. Please include:
We acknowledge legitimate reports within 5 business days and aim to remediate critical issues within 30 days.
The following are in scope for testing:
Out of scope:
If you make a good-faith effort to follow this policy and avoid privacy violations, destruction of data, and service disruption, we will not pursue legal action against you for security research. We will work with you to resolve the issue.
A security.txt file is published at /.well-known/security.txt.