Vulnerability Disclosure Policy
In short. If you find a security problem on this site, tell [email protected], give us a reasonable time to fix it, and we will not take legal action against you for research that follows this policy. There is no paid bounty.
Scope
This host and its subdomains: every page, the lease form, and the endpoint it posts to.
Out of scope
Denial of service or load testing; social engineering of anyone; physical attacks; and Cloudflare’s own infrastructure, which has its own disclosure program. Output of automated scanners with no demonstrated impact is not a report.
Rules
Stop at the minimum needed to demonstrate the issue. Do not read, change, or keep data that is not yours. Do not disclose the issue publicly before we have fixed it or 90 days have passed since your report, whichever comes first.
What we commit to
We acknowledge every report within 5 business days, keep you informed of what we find and when it is fixed, and will not pursue legal action against research that follows this policy in good faith.
How to report
Email [email protected] with the affected URL, the steps to reproduce, and what you were able to do. We read English.
To encrypt a report, use the OpenPGP key at
/security/pgp-key.txt, whose
fingerprint is 60c878b93afb97486eeccd196006b4249577d82c.
The same address, key, and this page are published in machine-readable form at /.well-known/security.txt (RFC 9116), signed with that key.