Report carefully
Website accounts use verified email and a password. Manage saved apps, support conversations and security in your account. Contact requests go to our support inbox; automatic reply emails are not enabled.
What to include
Describe the affected page or component, the steps to reproduce, the likely impact and a minimal example. Avoid real customer data. Do not include credentials, recovery codes or private files.
Keep testing bounded
Use accounts and data you control. Do not access other people’s information, disrupt services, attempt social engineering or leave persistent access behind. Stop when you have enough evidence to explain the issue.
Current website controls
The local service uses salted password hashing, hashed session and recovery tokens, same-origin request checks, CSRF protection, account ownership checks and request limits. These are implementation details, not a certification or a promise that no issue can exist.
No program promises
No bug-bounty reward, response-time guarantee or legal safe-harbor program has been announced. A formal disclosure policy and monitored contact must be confirmed before a public service launches.