LEGAL & TRUST
Vulnerability disclosure
Draft reporting page. A secure channel, scope, safe-harbor terms, response expectations, and key have not been approved.
- Status
- Draft — do not rely on this page as a reporting channel
- Last reviewed
- 2026-08-14
Reporting channel
The monitored contact is[SECURITY DISCLOSURE CONTACT — REQUIRED BEFORE PRODUCTION]. A secure submission method and, if adopted, public encryption key remain[SECURE REPORTING METHOD — REQUIRED BEFORE PRODUCTION].
Scope and authorization
Testing scope, excluded systems, testing methods, coordinated-disclosure rules, and authorization language are [DISCLOSURE SCOPE AND RULES — REQUIRED BEFORE PRODUCTION]. This draft does not grant authorization to test any system and does not promise safe harbor.
What a future report should contain
Once a channel is approved, a useful report would normally include:
- the affected URL or component and a concise description;
- reproduction steps and observed impact;
- non-sensitive supporting material; and
- a preferred contact method, if a response is requested.
Do not include client data, credentials, secrets, or unnecessary personal data.
Response and disclosure
No acknowledgement time, remediation SLA, bounty, status-update cadence, credit, or public-disclosure timeline is promised. Approved expectations remain[SECURITY RESPONSE AND DISCLOSURE PROCESS — REQUIRED BEFORE PRODUCTION].
Machine-readable policy
The production `/.well-known/security.txt` must identify a usable contact and approved expiry date. Its current policy link does not replace those unresolved fields. See also the Securitypage for product and website control status.