Security & Responsible Disclosure
We take the security of the platform and the safety of our users seriously.
Security contact
Report vulnerabilities privately to [email protected]. A PGP key will be published for encrypted reports.
Our commitment
- Acknowledge valid reports within 3 business days.
- Provide an initial assessment within 10 business days.
- Keep you informed until resolution.
Bug bounty
We do not operate a paid bug bounty program at this time, but we credit responsible reporters who wish to be acknowledged.