Responsible Disclosure

Last updated August 2026.

Our commitment

We build our own security the way we advise clients to. If you believe you have found a vulnerability in our website or infrastructure, we want to hear about it and will work with you in good faith.

How to report

Please report suspected vulnerabilities to the contact address in the site footer, with enough detail for us to reproduce the issue. Give us reasonable time to investigate and remediate before any public disclosure.

Scope and safe harbor

Testing must not harm our systems, our data or our users. Do not access, modify or exfiltrate data that is not yours, and do not run denial-of-service or automated scanning that degrades service. Good-faith research conducted within these limits will not be pursued by us.

What to expect

We will acknowledge a valid report, keep you informed of progress, and credit you if you wish once the issue is resolved.