Responsible Disclosure

Report a Vulnerability.

A direct route for security researchers and users who have found something we should know about.

Our Commitment

If you report a genuine security issue to us in good faith, we will acknowledge your report promptly and work with you to understand it. We will not pursue any action against you for having found it, provided you reported it to us rather than disclosing it publicly first, and did not access or damage data beyond what was necessary to demonstrate the issue.

Reports are triaged against a four-tier severity scale and handled by Technical Leadership directly. We aim to acknowledge every submission within two business days.


Your Details

We use this to respond to your report only.


The Vulnerability

Be as specific as you can. The more detail you include, the faster we can triage and act.

LowNo meaningful path to data or access
MediumAffects one non-critical component
HighPlausible path to personal data or privileged access
CriticalFull system, credential store, or database compromise

Not sure? Pick the closest match and explain in your description.

Include specific URLs, payloads, or request details where you can.

Reports go directly to Technical Leadership.

PGP Encryption

Your description and reproduction steps are automatically encrypted to our public key before they leave our server. Our public key is published at /security/pgp-public.asc if you prefer to encrypt them yourself; ciphertext pasted into the fields above is passed through untouched.