Policy

Security policy

How to report a security vulnerability in this website.

Last updated 19 September 2026

Reporting a vulnerability

If you believe you have found a security issue in this website, please report it privately through the contact form (choose "Report a security issue") or by email to the contact form. Include steps to reproduce and, if possible, the affected URL. Please do not access other people's data, degrade the service, or publish the issue before we have had a reasonable time to fix it.

What to expect

We acknowledge reports within a few working days, keep you informed of progress, and credit you if you wish once the issue is resolved. We will not take legal action against researchers who act in good faith and within this policy.

Out of scope

Issues in third-party sites we link to, volumetric denial of service, and reports generated solely by automated scanners without a demonstrated impact.