Responsible disclosure — submitted securely through Bugcrowd
Security research welcome

Help us protect our customers and services.

If you believe you have found a security issue, please share it through our responsible disclosure channel. We review reports carefully and aim to respond as quickly as possible.

Before you submit

Keep it focused, reproducible, and limited to the minimum testing required to demonstrate the issue.

Clear steps Include the affected asset, the exact steps to reproduce, and the observed behaviour.
Relevant evidence Screenshots or request/response examples help if they are concise and directly useful.
Low impact testing Avoid unnecessary access, disruption, persistence, or destructive actions.

Submission guidance

To help us triage quickly, include a short summary, the affected asset, reproduction steps, impact, and any supporting evidence.

  • 1
    Confirm scope Only submit issues that fall within the programme scope.
  • 2
    Describe impact Explain what an attacker could do, and why it matters.
  • 3
    Submit once Use the form below so the report routes into the right workflow.

Report form

A short delay is normal while the external script initializes