Responsible disclosure
Help us review potential security issues safely and responsibly.
Report safely
Use the consultation form and select Enterprise, then begin your message with “Security report.” Do not include exploit code, credentials, patient information, or other sensitive data in the initial message.
Good-faith research
Do not access, alter, download, or destroy data; disrupt services; use automated high-volume testing; test third-party services; or attempt social engineering. Stop immediately if you encounter sensitive information.
What to include
Provide the affected page or feature, a concise description of the issue, safe reproduction steps, and potential impact. We will arrange a secure communication channel if additional material is needed.
Our response
We will acknowledge credible reports, investigate them, and coordinate next steps where appropriate. This policy does not authorize activity that would otherwise be unlawful.