Make the report actionable
Identify the affected URL or component, prerequisites, minimal reproduction steps, observed impact and a safe suggestion for verification. Remove secrets, personal information and unrelated data from screenshots or proof.
OPEN SECURITY INTAKEDo not create consequence
Do not access, alter, retain or publish other people’s data; degrade service; use social engineering or phishing; test third-party systems; establish persistence; or demand payment. Stop when a finding is established and report it.
This policy is not blanket authorisation, a bug-bounty promise or permission to breach law or third-party terms. Good-faith, proportionate research that follows these boundaries will be handled as a coordinated security report.
What to expect
The target is to acknowledge a credible report within three business days, establish a private coordination path and provide a status update within ten business days. Remediation timing depends on severity and system ownership.
Public disclosure should be coordinated after a fix or agreed mitigation is available. There is currently no standing reward programme.
One canonical route
Automated security tooling can discover this policy through the RFC 9116 resource. It points to this HTTPS route rather than exposing a mailbox.
VIEW SECURITY.TXT