Responsible Disclosure Policy

How security researchers can report vulnerabilities safely.

Effective: 2026-08-05

Back to Security Center

Reporting Expectations

Researchers should provide reproducible steps, impact assessment, and proof-of-concept details where safe.

Testing must avoid privacy violations, service disruption, or data exfiltration.

Disclosure should remain confidential until remediation is complete.

Response Process

Reports are triaged by severity and acknowledged promptly.

Critical issues receive expedited remediation and incident coordination.

Reporter credit may be provided when legal and operationally appropriate.