Vulnerability Disclosure Policy
How to report a security problem, and what we promise in return.
How to report
Tell whoever operates this installation what you found, how to reproduce it, and what an attacker could achieve. Where the source is published, its own security contact is the right route for a flaw in the software itself rather than in one deployment of it.
There is no paid bounty programme, and no promise here about how quickly a particular operator will answer — that is theirs to make, not ours. What this policy does commit to is the undertaking below.
What we ask
- Use only accounts you own, or a test account you created for the purpose.
- Stop as soon as you have proof of a problem — do not access, change or delete other people’s data.
- Do not degrade the service: no denial-of-service testing, no load generation, no spam.
- Do not use social engineering against our people or our providers.
- Give us a reasonable chance to fix the problem before you tell anyone else. 90 days is normally plenty and we will usually be much quicker.
Our undertaking
If you follow this policy in good faith, we will treat your research as authorised, we will not pursue or support legal action against you for it, and we will work with you to understand and resolve the issue quickly. If a third party brings action against you for research conducted under this policy, we will make it known that you were acting within it.
This policy covers the service at this site. It does not authorise testing against our infrastructure provider’s own systems — report those to the provider.
Last updated 29 July 2026.