Principles
How to engage
- Act in good faith and avoid privacy violations, service disruption, or accessing data beyond what is necessary to demonstrate the issue.
- Give us reasonable time to remediate before you disclose publicly. We aim to acknowledge within 48 hours and provide fixes within 30 days.
- Do not modify or destroy data. If you encounter customer information, stop and notify us immediately.
- Never exploit a vulnerability beyond the minimal proof-of-concept needed for your report.
- Use only your own accounts when testing authentication or authorisation boundaries.