Coordinated disclosure
Security
Report vulnerabilities privately. Do not include private keys or exploit unrelated systems.
Report
Email [email protected] with affected endpoint, impact, reproduction steps, and a safe contact method. We will acknowledge reports when the mailbox is operational.
Safe testing
Use the smallest proof necessary. Do not access other users’ data, degrade service, perform denial-of-service testing, or publish an unresolved issue before coordination.
Verification
Signed application receipts publish verification keys at /v1/receipts/jwks.json.