Security and reporting
Report platform vulnerabilities and abuse through the official contact channel.
Report a vulnerability
Send a concise report to [email protected] with subject Security. Include the affected public URL, steps to reproduce and expected versus observed behaviour. Remove personal data and secrets from screenshots or logs.
Responsible disclosure
Avoid disruptive tests, denial of service, accessing other accounts or extracting private data. Stop when a minimal demonstration establishes the issue. There is no published bug bounty or guaranteed response time.
Current protections
Passwords are stored as salted hashes. The application uses authenticated sessions, request verification and server-side payment reconciliation. Provider credentials and the database are outside the public web directory. These controls do not guarantee that every vulnerability is absent.
Last updated: 2026-10-11