How to report

Use the main-site contact form and choose Security report. Provide a concise description, affected public URL/product and safe reproduction steps. Do not paste active credentials, API keys, customer data or exploit payloads containing sensitive information into the form.

Safe-harbor boundary for public testing

The public demo may be used for ordinary functional testing. Do not perform destructive exploitation, denial-of-service testing, credential attacks, social engineering, automated high-volume scanning or attempts to access data/accounts you do not own or control.

What a report is not

A report does not create a bug-bounty payment obligation or a security certification relationship. If a formal security program or bounty is launched later, it will be published separately.

Production customers

There are currently no public claims that the public-beta site is a production-grade security boundary for third-party systems. Any future production deployment requires separate security and operational review.

← Submit a security report