Skip to content

Report a security vulnerability

Before you write: the rules and our commitment not to pursue you are on a page of their own. In short: if you look in good faith and within those rules, you will face no legal action from us. Separate rules apply to sites we operate for clients.

A human will review your report within five working days; reports describing access to personal data or an ongoing exploitation we look at with priority, outside business hours as well. You need no account and no address - without an address, though, we cannot reply to you.

What happens to your details is set out in the "Security Vulnerability Reporting" section of our privacy policy.

Where exactly does the finding occur?

What does an attacker achieve?

Expected and actual behaviour, step by step.

Is the flaw being exploited right now? (required)

If yes, hours count instead of working days - your report takes the fast track.

Was personal data visible in the process? (required)

Even accidentally and even briefly. Starts a statutory deadline.

Please redact other people's credentials first.

Optional. Without an address we cannot ask follow-up questions; your case number remains your proof.

The check sends this form's contents once to our model provider (OpenRouter, processing outside the EU possible). It runs only on this click and is optional - you can submit the report without it at any time.