Disclosure
Security
If you find a vulnerability in this site, our mail, or a system we operate, write us and choose Security as the topic.
Do not
- Open a public GitHub issue that contains live credentials, session tokens, or customer data
- Access data that is not yours, or keep a copy once you have shown the issue
- Run destructive tests against mail or payment flows
Do
- Send enough to reproduce, and a contact we can reply to
- Give us a reasonable window before public discussion
We will acknowledge. We do not run a paid bounty program today; we will still treat a good report as a report, not as noise.