We welcome reports from security researchers and customers. Submit the form and it goes straight to our team, we'll investigate, keep you updated, and fix it. We won't pursue action against anyone acting in good faith to help us keep the platform safe.
Prefer email? Write to [email protected].
Machine-readable details: /.well-known/security.txt
We don't run a paid bug-bounty program at this time, but we're genuinely grateful for responsible reports and will gladly credit you for a valid finding if you'd like to be named.