Security
Found a vulnerability? Thank you for reporting it privately.
Report a vulnerability
with:
- the affected page, endpoint or app version;
- steps to reproduce, and what an attacker could achieve;
- how you would like to be credited, if at all.
We acknowledge reports within 5 working days and keep you informed until the issue is fixed. Please give us a reasonable time to fix it before telling anyone else.
Please do not
- access, change or delete data that is not yours;
- run denial-of-service tests or automated scans that degrade the service;
- use social engineering, phishing or physical attacks.
We will not take legal action against research done in good faith within these rules.
How the site is protected
- HTTPS only, enforced with HTTP Strict Transport Security.
- A strict Content Security Policy with a new nonce on every request.
- Framing blocked, MIME sniffing disabled and unused browser features switched off.
- Business logic that must stay private runs on the server, never in the browser.