Skip to main content

Trust & safety

Security

Report suspected vulnerabilities to [email protected]. Include affected URLs, reproduction steps, impact, and any logs or screenshots that help us verify the issue quickly.

Reporting scope

  • Public Codebase Design web, API, workspace, settings, publish, and CDN surfaces.
  • Authentication, authorization, data isolation, build isolation, and deployment controls.
  • Security headers, privacy-sensitive data exposure, and production configuration issues.

Responsible disclosure

  • Do not access, modify, delete, or exfiltrate data that is not yours.
  • Do not run denial-of-service, spam, social engineering, or physical security tests.
  • Give us a reasonable window to validate and remediate before public disclosure.