Security
Responsible disclosure
Security is our trade : starting with our own systems. If you believe you have found a vulnerability on this website, we thank you for reporting it responsibly.
How to report
Write to [email protected] with a reproducible description (URL,
steps, estimated impact). The file
/.well-known/security.txt (RFC 9116) lists these
contact details.
Our commitments
Acknowledgement within 2 business days; fixes prioritized by severity; no legal action for good-faith research that follows the rules below; public credit if you wish.
Rules of engagement
No exfiltration of real data, no availability impact (denial of service), no social engineering or phishing of our teams or clients, no persistent access. Limit testing to what is strictly necessary to demonstrate the vulnerability.