Disclosure process
Security contact
Use the dedicated security route and include a safe description, affected public surface, and reproduction steps.
Learn moreSupported systems
Only public ResBased services explicitly named in the current security scope.
What not to test
No denial of service, social engineering, destructive action, persistence, credential access, privacy invasion, or testing of third-party systems.
Expected response
Acknowledgment, triage, scope confirmation, remediation coordination, and an approved disclosure decision.
Program boundary
No bug bounty, payment, safe-harbor expansion, authorization to access data, or permission to test is offered unless an explicit written program states it.