Security
Draft — pending studio sign-offReporting a vulnerability
If you believe you've found a security issue affecting this website, we want to know about it. Please report it through the contact form, with a subject line starting with "Security:", and include:
- A description of the issue and its potential impact
- Steps to reproduce it
- Any relevant request/response details or proof-of-concept
Our commitment
We'll acknowledge good-faith reports, investigate promptly, and won't pursue legal action against researchers who report issues responsibly and avoid privacy violations, data destruction, or service disruption while testing.
Out of scope
Automated vulnerability scanning that degrades site performance, social engineering against staff, and physical security testing are not authorized.
Machine-readable disclosure info
Per RFC 9116, this page
is also referenced from /.well-known/security.txt. We don't have a dedicated
security email yet, so it points back to this page's reporting process — that will be
replaced with a direct contact once one exists.