Security Policy
How to report vulnerabilities responsibly.
Last updated 1 July 2026
Responsible disclosure
If you discover a vulnerability, report it privately to our security contact and give us reasonable time to remediate before disclosure. We will not pursue legal action against researchers who follow this policy in good faith.
Scope
Reports about this website and its accounts, payments, and member features are in scope. Findings in third-party services we use should be reported to those providers.
This document is a plain-language template and does not constitute legal advice. It should be reviewed and adapted by qualified counsel before the platform launches.