Legal review notice: This placeholder disclosure policy should be reviewed by legal and security leadership before production use.
1. Responsible Disclosure
If a security researcher or customer identifies a potential vulnerability in the platform, the preferred approach is coordinated, private disclosure through the designated security contact. Public disclosure timelines should be agreed in good faith.
2. Submission Guidelines
Reports should include affected URLs or features, reproduction steps, observed impact, and any supporting evidence. Submitters should avoid accessing data beyond what is necessary to confirm the issue and should not disrupt service availability.
3. Out-of-Scope Conduct
Unauthorized data access, denial-of-service activity, social engineering against staff, malware submission, or attempts to obtain real credentials are out of scope and prohibited.
4. Contact Placeholder
Replace this section with the actual security reporting address, PGP or encrypted-submission instructions if used, and expected response windows.