Legal

Security

Draft — pending studio sign-off

Reporting a vulnerability

If you believe you've found a security issue affecting this website, we want to know about it. Please report it through the contact form, with a subject line starting with "Security:", and include:

Our commitment

We'll acknowledge good-faith reports, investigate promptly, and won't pursue legal action against researchers who report issues responsibly and avoid privacy violations, data destruction, or service disruption while testing.

Out of scope

Automated vulnerability scanning that degrades site performance, social engineering against staff, and physical security testing are not authorized.

Machine-readable disclosure info

Per RFC 9116, this page is also referenced from /.well-known/security.txt. We don't have a dedicated security email yet, so it points back to this page's reporting process — that will be replaced with a direct contact once one exists.