011. Scope
This policy covers our own corporate website and infrastructure. For vulnerabilities found in a specific client product, please contact that organization directly unless we have been explicitly authorized to receive reports on their behalf.
022. How to Report
Send a detailed report to our security team, including steps to reproduce, potential impact, and any proof-of-concept material, using the security contact listed on our Contact page.
033. What to Expect
We acknowledge reports within two business days, provide an initial assessment within five business days, and keep the reporter informed of remediation progress until the issue is resolved.
044. Responsible Testing Guidelines
Please avoid accessing, modifying, or deleting data that does not belong to you, avoid disrupting production services, and give us reasonable time to remediate before any public disclosure.
055. Safe Harbor
We will not pursue legal action against researchers who make a good-faith effort to comply with this policy while identifying a vulnerability.
