How to report
- 01Email our security team
Send details to our security contact. Include steps to reproduce, affected URLs and any proof-of-concept. One clear report is worth more than ten vague ones.
- 02Give us time to respond
We will acknowledge your report and keep you updated as we investigate and remediate. Please do not disclose publicly until we have had a reasonable chance to fix the issue.
- 03We fix and credit
Once resolved, we are happy to credit your contribution if you wish. We treat good-faith researchers as partners, not adversaries.
Safe harbour
Acting in good faith under this policy, you can expect:
Scope and expectations
Please test only against your own account and data. Do not access, modify or delete other users’ data, degrade the service, or run automated scans that disrupt availability. Social engineering, physical attacks and denial of service are out of scope.
We do not currently run a paid bug-bounty programme. We will always acknowledge valid reports and credit researchers who wish to be named.
Report a security issue
Prefer to reach a human first? Our team will route you to security.