Security and responsible disclosure

Last updated: 25 September 2026.

Report a suspected vulnerability privately to [email protected]. The machine-readable contact is at security.txt.

What to include

Send the affected URL, a short description, minimal reproduction steps, expected impact and a way to contact you. Use a test account and redact personal data, credentials and tokens. Ask for a secure channel before sending sensitive evidence.

Research boundaries

Stop once you have enough evidence. Do not access, change or retain other people's data. Do not run denial-of-service attacks, bulk automated scans, social engineering or tests against our providers. Do not demand payment or threaten disclosure. If you encounter personal data accidentally, stop and report the exposure without copying it.

How we respond

We aim to acknowledge reports within five working days, assess their impact and coordinate remediation and publication with you. This is a target, not a guaranteed response time. There is no paid bug bounty programme. These guidelines do not authorise unlawful access or bind third parties.

Technical protections and limits

The website uses browser security headers, per-request script nonces, origin checks for browser API writes and per-process request limits. Payment webhook messages are checked using their signature. Server credentials are not intended for the browser. These controls do not establish that hosting, backups or stored data have been independently audited or certified.

For privacy requests use [email protected]. For urgent personal safety concerns, use the emergency contacts.