Security

Found a vulnerability? Thank you for reporting it privately.

Report a vulnerability

with:

  • the affected page, endpoint or app version;
  • steps to reproduce, and what an attacker could achieve;
  • how you would like to be credited, if at all.

We acknowledge reports within 5 working days and keep you informed until the issue is fixed. Please give us a reasonable time to fix it before telling anyone else.

Please do not

  • access, change or delete data that is not yours;
  • run denial-of-service tests or automated scans that degrade the service;
  • use social engineering, phishing or physical attacks.

We will not take legal action against research done in good faith within these rules.

How the site is protected

  • HTTPS only, enforced with HTTP Strict Transport Security.
  • A strict Content Security Policy with a new nonce on every request.
  • Framing blocked, MIME sniffing disabled and unused browser features switched off.
  • Business logic that must stay private runs on the server, never in the browser.