Vulnerability disclosure

We take the security of this application seriously. If you believe you have found a vulnerability, we want to hear from you.

How to report

Email a description of the issue, the steps to reproduce it, and its potential impact to the contact listed in our security.txt. Please give us reasonable time to respond before any public disclosure.

Scope

In scope: the application and its authentication and data-handling flows. Out of scope: automated scanner output without a working proof of concept, denial-of-service, social engineering, and issues in third-party services we do not control.

What to expect

We will acknowledge your report, keep you updated as we investigate, and let you know when the issue is resolved. We do not run a paid bug-bounty program.

Safe harbor

If you make a good-faith effort to comply with this policy during your research, we will consider your testing authorized, work with you to resolve the issue promptly, and will not pursue legal action against you.