Reporting
Email your finding to [EMAIL ADDRESS] with a description, the steps to reproduce the issue and, if you wish, your name for credit. For sensitive details use our PGP key if listed on this page, or ask for it. Machine-readable: /.well-known/security.txt.
What we promise
We reply within one business day, keep you informed of progress and fix confirmed vulnerabilities as quickly as possible, usually within 30 days. We take no legal action against reporters who follow these rules and credit you, if you wish, after the fix.
What we ask of you
Go no further than needed to demonstrate the issue; do not copy, modify or delete data; do not use social engineering, spam, DDoS or physical attacks; do not share the vulnerability with others before it is fixed; report it as soon as possible.
Out of scope
Reports about missing best-practice headers without demonstrable impact, version numbers, automated scanner output without a proof of concept, and vulnerabilities in third-party services (hosting, email) we do not manage.