Security & Responsible Disclosure

Report a vulnerability

Please test only against your own account, use the smallest amount of data needed to demonstrate the issue, do not run automated scans that degrade the service for others, and give us a reasonable window before publishing. We will not pursue legal action against researchers who follow this. We do not currently run a paid bounty programme, and we will credit you if you would like that.

What we do

What we do not claim

What you can do