Report a vulnerability
Email security@tensabyte.com with a clear description, affected URL or component, reproduction steps, impact, and any suggested remediation. Do not include secrets in the first message. We will acknowledge a credible report and coordinate next steps.
Good-faith research
We support research intended to improve security. Please use the minimum interaction and data necessary to demonstrate an issue, stop if you encounter personal or confidential information, and give us reasonable time to remediate before public disclosure.
Out of scope
- denial-of-service, load testing, spam, or resource exhaustion;
- social engineering, phishing, physical attacks, or credential stuffing;
- accessing, changing, retaining, or publishing another user's data;
- automated scanning that materially degrades the service; and
- issues solely in a third-party service with no demonstrated impact here.
What you can expect
For good-faith research that follows this policy, we will not initiate legal action solely because you reported the issue. This does not authorise access to third-party systems, exempt anyone from applicable law, or promise a reward.