Responsible Disclosure
Last updated August 2026.
Our commitment
We build our own security the way we advise clients to. If you believe you have found a vulnerability in our website or infrastructure, we want to hear about it and will work with you in good faith.
How to report
Please report suspected vulnerabilities to the contact address in the site footer, with enough detail for us to reproduce the issue. Give us reasonable time to investigate and remediate before any public disclosure.
Scope and safe harbor
Testing must not harm our systems, our data or our users. Do not access, modify or exfiltrate data that is not yours, and do not run denial-of-service or automated scanning that degrades service. Good-faith research conducted within these limits will not be pursued by us.
What to expect
We will acknowledge a valid report, keep you informed of progress, and credit you if you wish once the issue is resolved.