Security reports go through the contact form with “Security report” selected — they are routed to a separate inbox rather than the general one, so they are not sitting behind ordinary support mail, and a human replies to every one.
Please give us a reasonable window to fix an issue before disclosing it publicly. We will tell you what we found, what we changed, and when — and we will not threaten you for reporting in good faith.
Did this answer it?
If not, write in. The reply comes from the person who built the feature.
Message us