Report responsibly
Report a reproducible vulnerability without accessing data beyond what is necessary to demonstrate the issue. Do not exfiltrate data, disrupt service, social-engineer staff, or publish details before a fix is coordinated.
Policy
Good-faith reports help protect source submitters, editorial systems, and public readers.
Report a reproducible vulnerability without accessing data beyond what is necessary to demonstrate the issue. Do not exfiltrate data, disrupt service, social-engineer staff, or publish details before a fix is coordinated.
We triage the report, preserve relevant logs without exposing private data, assess impact, and communicate remediation progress through the configured disclosure channel.
The public web Worker, editorial APIs, authentication flow, source intake, and media delivery are in scope. Third-party services remain subject to their own reporting policies.
A production deployment must publish a monitored security contact and response target before this policy can accept reports.