Skip to content

Security

Acknowledgments.
Credit where it is due.

When someone reports a vulnerability to us in good faith, we credit them here when we publish the fix, under the name or handle they choose, unless they would rather we did not.

What you get from us

What we commit to.

The same four commitments as the disclosure policy on the contact page, repeated here because this is the page a researcher lands on first.

  • An acknowledgement in two business days.

    A person confirms your report has been read. Not an autoresponder, and not silence while somebody works out who owns it.

  • An assessment in ten business days.

    Our reading of the severity and a remediation timeline. If we disagree with your assessment we will say why rather than closing the thread.

  • No legal action for good-faith research.

    We will not pursue legal action against researchers acting in good faith within the scope published on the contact page.

  • Credit here when the fix ships.

    Under the name or handle you choose, or not at all if you would rather stay anonymous. Your call, and we will ask.

How to report

Where to send it.

Email [email protected]. The scope, the exclusions and what we ask you not to do are on the contact page, alongside the machine-readable security.txt.

If you would rather encrypt the report, our public key is at /pgp-key.txt: RSA 4096, fingerprint 0BF9 2313 F076 6537 2962 EAF7 29B2 4751 7B06 409C, valid until 18 September 2028.

We do not run a paid bug bounty. Saying so plainly is better than implying one and disappointing the person who found something.

Found something? We will not be difficult about it.