Good-faith research
Limit testing to the minimum necessary to demonstrate a suspected issue. Stop when you encounter personal, confidential, or third-party information and report the finding privately.
Disclosure policy
These guidelines define a respectful path for reporting suspected security issues affecting systems we operate.
Limit testing to the minimum necessary to demonstrate a suspected issue. Stop when you encounter personal, confidential, or third-party information and report the finding privately.
Denial of service, social engineering, physical attacks, spam, automated account creation, destructive testing, privacy violations, and testing third-party systems without authorization are not permitted.
Give us reasonable time to assess and address a credible report before publishing details. Do not publicly disclose information that could increase risk while an issue remains unresolved.
We do not currently operate a bug bounty program. Recognition may be offered only with the reporter’s permission and at our discretion; no payment or acknowledgement is guaranteed.