Report a vulnerability
How to report
Email [email protected] with "security" in the subject line. The same address is published in machine-readable form at /.well-known/security.txt.
Please include what you found, the steps to reproduce it, and what an attacker could do with it. A proof of concept helps enormously. If a report is ambiguous we will ask rather than guess, so the more concrete the reproduction, the faster it moves.
What happens next
We acknowledge reports and work through them in order of how much harm they can do. We will tell you what we concluded, including when we decide something is not a vulnerability and why.
We do not run a paid bug bounty and we would rather say so plainly than leave it implied. There is no reward, and no fixed remediation deadline we can honestly commit to.
Please do
- Test only against your own account, your own device, and data you own.
- Give us a reasonable chance to fix an issue before you publish it.
- Stop as soon as you have shown a problem exists. Do not go further into an account or a device that is not yours to measure how bad it is, tell us instead.
Please do not
- Access, modify, or delete data belonging to anyone else, or degrade service for anyone else.
- Run denial-of-service, load, or automated scanning traffic against our endpoints.
- Use social engineering, phishing, or physical access against our staff or our users.
Out of scope
Reports that amount to a scanner's output with no demonstrated impact, missing security headers with no exploit path, and issues in third-party services we do not operate are out of scope. For a third-party service, please report it to whoever runs it. We will help you find the right contact if that is not obvious.
An app running on a device the user controls is not a boundary we claim to defend: the device owner can already read and change what is on their own device, and that is by design rather than a flaw.