Responsible disclosure
If you believe you found a security issue, send a concise report with the affected URL, reproducible steps, impact, and any non-sensitive evidence. Do not access another customer’s data, run destructive tests, or disclose a potential issue publicly before we can investigate.
Use the monitored address published in our security.txt file.
Remove passwords, tokens, signing keys, and private customer data from evidence.
We will acknowledge actionable reports and coordinate remediation communication in good faith.