Security
Disclosure
We care about security and service stability. If you believe you found a vulnerability, please report it responsibly using the channel below.
Last updated: 2026-04-01
1. Principles
- Data minimization: collect only what is needed to provide the service.
- Least privilege: limit access by role and responsibility.
- Continuous improvement: improve based on monitoring, audits, and feedback.
2. Responsible disclosure
Include
- Impact and potential consequences
- Steps to reproduce and a minimal PoC (optional)
- Screenshots and request/response samples (redact secrets)
3. Response process (example)
- 1) Acknowledge and triage: typically within 3 business days.
- 2) Reproduce and assess severity.
- 3) Fix, deploy, and confirm resolution.