Report a Vulnerability.
A direct route for security researchers and users who have found something we should know about.
If you report a genuine security issue to us in good faith, we will acknowledge your report promptly and work with you to understand it. We will not pursue any action against you for having found it, provided you reported it to us rather than disclosing it publicly first, and did not access or damage data beyond what was necessary to demonstrate the issue.
Reports are triaged against a four-tier severity scale and handled by Technical Leadership directly. We aim to acknowledge every submission within two business days.
Your description and reproduction steps are automatically encrypted to our public key before they leave our server. Our public key is published at /security/pgp-public.asc if you prefer to encrypt them yourself; ciphertext pasted into the fields above is passed through untouched.