Security
Security
If you have found a weakness in something of ours, we want to hear about it.
How to report
Use the contact form and begin your message with the word security. Those are read first. If you work with automated tooling, the machine-readable details are published at /.well-known/security.txt.
What we will do
- Acknowledge your report within three working days.
- Tell you what we found and what we are doing about it.
- Credit you when the fix ships, if you would like to be credited.
What we ask
- Give us a reasonable chance to fix it before telling anyone else.
- Do not access, change or delete data that is not yours.
- Do not run tests that degrade the service for other people.
- Bulk automated scanning helps neither of us. Please do not.
Good faith
Research carried out honestly and within the lines above is welcome, and we will not pursue legal action over it. If you are unsure whether something is in bounds, ask first.