Trust center / Disclosure

Report security concerns safely.

Good-faith research that respects privacy, avoids disruption and gives us a reasonable opportunity to respond is welcome.

Contact

Email [email protected] with “Security report” in the subject. Include the affected route or component, reproducible steps, impact, and a safe proof of concept. Do not include other users’ content or active credentials.

Research guidelines

  • Use accounts and data you control.
  • Stop if you encounter personal data, secrets or cross-tenant access and report immediately.
  • Do not degrade availability, send unsolicited messages, run high-volume scanners, persist access or alter production data.
  • Do not publicly disclose an unresolved issue before a coordinated timeline is agreed.

In scope

The canonical web application, documented API, official browser extension and their authentication, authorization, isolation and data-handling boundaries.

Usually out of scope

Purely theoretical findings, missing best-practice headers without a demonstrated impact, provider-wide issues outside our control, social engineering, rate testing that risks disruption, and reports generated solely by unvalidated automated scans.

Response target

We aim to acknowledge actionable reports within five business days. This is an operational target, not a service-level agreement or bounty promise.