SECURITY
Report security concerns responsibly.
Good-faith reports help protect clients and the service. Please provide enough detail to reproduce and assess the issue without accessing other people’s information.
Last updated 8 August 2026How to report
Use the secure enquiry form and begin the message with “Security report”. Include the affected URL, observed behaviour, reproduction steps, impact and a safe way to contact you.
Please avoid
Do not access, modify, retain or disclose another person’s data; degrade the service; use denial-of-service testing; run destructive payloads; or use social engineering. Stop testing if private information becomes visible.
What happens next
The report will be triaged and acknowledged when contact information is provided. Remediation timing depends on severity, reproducibility and platform dependencies. Public disclosure should be coordinated until affected users are protected.
Supported scope
The current security contact, canonical policy and expiry date are published at /.well-known/security.txt.