Responsible Disclosure Policy

This page is for security researchers interested in reporting application security vulnerabilities. This is intended for application security vulnerabilities only.

The details within your request form will be submitted to (operated by an independent third party, Synack). If you have reported an issue determined to be within program scope and to be a valid security issue, will validate your finding and you will be allowed to disclose the vulnerability after a fix has been issued. This process is managed exclusively by through their platform, accordingly you must accept the terms of service if you wish to proceed. All queries are to be directed to and managed exclusively through the online portal.

Typical Vulnerabilities Accepted

  • OWASP Top 10 vulnerability categories
  • Other vulnerabilities with demonstrated impact

Typical Out of Scope

  • Theoretical vulnerabilities
  • Informational disclosure of non-sensitive data
  • Low impact session management issues
  • Self XSS (user defined payload)

For a full list of program scope please visit the Responsible Disclosure details page.

Responsible Disclosure Guidelines

  • Adhere to all legal terms and conditions outlined at
  • Work directly with on vulnerability submissions
  • Provide detailed description of a proof of concept to detail reproduction of vulnerabilities
  • Do not engage in disruptive testing like DoS or any action that could impact the confidentiality, integrity or availability of information and systems
  • Do not engage in social engineering or phishing of customers or employees
  • Do not store, share, compromise, or destroy Impact customer data
  • Do not initiate any fraudulent financial transactions
  • Do not disclose the potentially identified security vulnerability with third parties
  • Do not request compensation for time and materials or vulnerabilities discovered