Security
Security
How this site is protected, and how to report something you have found.
Reporting a vulnerability
Send a description and reproduction steps to the security address below. We acknowledge reports within two business days. Please do not test against production data or attempt to access another person's account.
Measures in place
- HTTPS enforced with strict transport security across every route.
- Content security policy, frame denial and MIME sniffing protection on all responses.
- Bot verification and rate limiting on every public form.
- Secrets held in the hosting provider's environment store, never in the repository.
- Dependency and secret scanning on every change in continuous integration.
