Vulnerability Disclosure Policy

How to report a security problem, and what we promise in return.

How to report

Tell whoever operates this installation what you found, how to reproduce it, and what an attacker could achieve. Where the source is published, its own security contact is the right route for a flaw in the software itself rather than in one deployment of it.

There is no paid bounty programme, and no promise here about how quickly a particular operator will answer — that is theirs to make, not ours. What this policy does commit to is the undertaking below.

What we ask

Our undertaking

If you follow this policy in good faith, we will treat your research as authorised, we will not pursue or support legal action against you for it, and we will work with you to understand and resolve the issue quickly. If a third party brings action against you for research conducted under this policy, we will make it known that you were acting within it.

This policy covers the service at this site. It does not authorise testing against our infrastructure provider’s own systems — report those to the provider.

Last updated 29 July 2026.

All policies · Sign in