Contact
Email [email protected] with “Security report” in the subject. Include the affected route or component, reproducible steps, impact, and a safe proof of concept. Do not include other users’ content or active credentials.
Research guidelines
- Use accounts and data you control.
- Stop if you encounter personal data, secrets or cross-tenant access and report immediately.
- Do not degrade availability, send unsolicited messages, run high-volume scanners, persist access or alter production data.
- Do not publicly disclose an unresolved issue before a coordinated timeline is agreed.
In scope
The canonical web application, documented API, official browser extension and their authentication, authorization, isolation and data-handling boundaries.
Usually out of scope
Purely theoretical findings, missing best-practice headers without a demonstrated impact, provider-wide issues outside our control, social engineering, rate testing that risks disruption, and reports generated solely by unvalidated automated scans.
Response target
We aim to acknowledge actionable reports within five business days. This is an operational target, not a service-level agreement or bounty promise.