Operational proceduresPublic procedureNo index
Responsible Vulnerability Disclosure Procedure
How security researchers can report suspected vulnerabilities safely.
Last reviewed: 23 July 2026
Reporting
Report suspected vulnerabilities through the Contact page with a clear security label, affected URL or component, reproduction steps, impact and any safe proof. Do not include customer data in the report.
Research boundaries
- Do not access, alter, retain or disclose other users’ data.
- Do not perform denial-of-service, social engineering, phishing or physical testing.
- Do not use destructive payloads or persistence.
- Stop testing and report immediately if customer data or credentials are encountered.
- Allow reasonable time for investigation before public disclosure.
Our response
We will acknowledge credible reports, triage impact, investigate and communicate material progress where practicable. This procedure is not a bug-bounty promise and does not authorise unlawful access.