Security
Security Disclosure Policy
How to report security vulnerabilities responsibly.
Last reviewed: October 2026
Reporting a vulnerability
If you believe you have discovered a security vulnerability, please report it responsibly. Do not publicly disclose the vulnerability until it has been addressed.
What to include
Include a description of the vulnerability, the steps to reproduce it, and the potential impact. If possible, include a proof of concept.
Response timeline
We aim to acknowledge receipt of vulnerability reports promptly. We do not promise a specific remediation timeline, but every report is taken seriously and evaluated in order of severity.
Safe harbor
We appreciate responsible disclosure. We will not pursue legal action against individuals who report vulnerabilities in good faith and in accordance with this policy.
Scope
This policy applies to this website and the platform described on it. It does not apply to third-party services or providers.
Need to report a vulnerability?
Contact us through the contact page with details of the issue.