Do you have a bug bounty program?
We do not currently run a bug bounty program, and we do not offer guaranteed monetary compensation for reported vulnerabilities. We will not negotiate payment in exchange for the details of a reported issue.
Reporting a security issue
We do welcome good-faith reports of genuine security issues. If you believe you have found a vulnerability, please send a written report to [email protected] that includes:
A clear description of the issue.
Step-by-step instructions to reproduce it.
The potential impact (what an attacker could actually do).
Any relevant URLs, requests, or screenshots.
Reports that contain these details will be reviewed. Generic messages that only ask whether we pay, automated scanner output with no demonstrated impact, or requests to move the conversation to a live agent without a concrete report will not be actioned.
Ground rules
Do not access, modify, or delete data that does not belong to you.
Do not degrade or disrupt our service (no DoS, spam, or social engineering of our staff or users).
Give us reasonable time to respond before any public disclosure.
Thank you for helping keep the service safe.
