Guidelines for ethical vulnerability research and reporting
1Scope & Authorization
•Only test against programs that are listed as “Active” on this platform
•Stay within the defined scope for each program — out-of-scope testing may result in account suspension
•Do not access, modify, or delete data belonging to other users
•Create your own test accounts when testing authentication-related vulnerabilities
2Reporting Guidelines
•Provide detailed reproduction steps, including screenshots and proof-of-concept code
•Include the impact assessment with a clear CVSS score
•Submit one vulnerability per report
•Do not publicly disclose the vulnerability before the program has confirmed the fix
3Prohibited Actions
✕Denial of Service (DoS/DDoS) attacks
✕Social engineering or phishing attacks against employees
✕Physical attacks against infrastructure
✕Automated vulnerability scanning without permission
✕Exfiltrating user data beyond what is necessary to demonstrate the vulnerability
4Safe Harbor
We consider activities conducted consistent with this policy to be “authorized.” We will not pursue civil action or initiate a complaint against you for activities conducted in accordance with this policy. If legal action is initiated by a third party against you in connection with activities conducted under this policy, we will take steps to make it known that your actions were conducted in compliance with this policy.