Trust

Responsible disclosure

How to report a vulnerability, and what we commit to in return.

If you have found a way to reach data you should not reach, to act as an account that is not yours, or to make the agent do something it must not do, we want to hear about it before anyone else does. Write to [email protected]. There is no form and no account required.

What we commit to

We do not operate a paid bug bounty. We would rather tell you that plainly than imply a reward that does not exist.

In scope

Out of scope

Rules for testing

What to include

A description of the issue and its impact, the exact steps or requests needed to reproduce it, the account or URL involved, timestamps, and anything else that would let an engineer see it happen. Screenshots and a short recording help. Write in English or Hungarian.

After a report

We reproduce it, assign severity, fix it, and — where customer data was affected — follow the notification path in security and clause 8 of the data processing addendum. Where a fix changes how the product behaves, it appears in the changelog. Where it changes a commitment, it appears on the page that made the commitment.

Testing conducted within this policy is authorised, and clause 5 of the acceptable use policy is disapplied to that extent. Anything outside this scope is not authorised.