Security and responsible disclosure
How to report a suspected vulnerability safely.
Effective and updated: · Version: 2026-10-01.1
Human review required: operator details and binding legal translations are not yet confirmed.
Report privately
Use the security contact below or the contact path listed in /.well-known/security.txt. Include the affected URL, impact and minimal reproduction steps without secrets or other people’s data. Stop testing if you encounter private data. Do not exploit, disrupt service or disclose personal information.
Scope and expectations
Test only accounts and data you control. Do not send provider keys. No bounty, response deadline, legal safe harbor or permission to access another system is promised. Operator contact configuration and disclosure handling require human review.