If you have found a security issue, and it's not already known, then please send a report to [click to see email address].


We will investigate legitimate reports and make every effort to quickly resolve any vulnerability. To encourage responsible reporting, we will not take legal action against you nor ask law enforcement to investigate you provided you make a good faith effort to avoid causing harm to us, our users, and anyone else. This includes avoiding privacy violations, destruction of data, and interruption or degradation of services.


The following test types are excluded from the scope:

The following issue types are excluded from scope:

We encourage hackers to read Web Hacking 101 and Breaking into Information Security: Learning the Ropes 101 to get a good idea of the type of issues that we are looking for.

We may modify the above guidelines at any time. Last update: January 18, 2018.

Hall of Fame

Thanks to the following researchers (most recent first) for having reported security issues to us via email:

