Scope
- In scope: this website and its subdomains.
- Out of scope: denial of service, physical attacks, social engineering of any person, automated scanning that degrades availability, and reports generated solely by a scanner with no demonstrated impact.
What to send
- The affected URL or component and a clear description of the issue.
- Reproduction steps, and the smallest proof of concept that demonstrates impact.
- Your assessment of the impact, and whether any data was accessed.
What you can expect
- Acknowledgement within two working days.
- An assessment and a remediation timeline within seven working days.
- Credit in the fix note if you want it, and no legal action for good-faith research within this policy.
Client systems
If you have found an issue in a system tested through this practice, send it here and it will be forwarded to the affected party under coordinated disclosure. Client details are never confirmed or denied.
Machine-readable
The same contact details are published at /.well-known/security.txt per RFC 9116.