Security & trust.
Security claims should be evidence-backed, scoped and current.
Public reader boundary
The public reader is separated from private editorial routes. Production controls require an approved host, exact release revision, AAP execution, strict host-key verification, release acceptance evidence and independent specialist review before deployment.
Report a suspected vulnerability
Use the contact route and identify the affected URL or component, the observed behavior, reproducible steps that do not expose other people’s data, and the potential impact. Do not include passwords, private keys, confidential records or exploit data belonging to another party.
This page welcomes responsible reports; it does not authorize disruptive testing, denial of service, social engineering, persistence, access-control bypass against third-party infrastructure, or access to data that is not yours. No bug-bounty payment or response-time commitment is implied unless separately agreed in writing.
Current assurance boundary
Application security controls, automated regression tests and operational evidence are not a penetration-test report, SOC 2 report, ISO 27001 certificate, legal opinion or customer-specific risk assessment. Enterprise assurance material should state what was actually tested, when it was tested, and which release the evidence covers.
Open security.txt ↗