1. How to report
The security contact address and the PGP key for encrypted reports.
How to report a security vulnerability to us safely, what we commit to in return, and what is out of scope.
Draft outline — not yet legally binding. This page lists the sections this document must contain. The operative text needs your legal entity name, registered address and Grievance Officer details, and must be reviewed by counsel before publication. Send us those details and we will complete it.
The security contact address and the PGP key for encrypted reports.
Acknowledgement timeline, status updates, and no legal action for good-faith research.
Which domains and systems are in scope, and which are explicitly excluded.
Report types we do not act on, stated plainly so nobody wastes their time.
Questions about this document? Write to [email protected].