Reporting a vulnerability¶
Send a minimal, non-public report through the security contact listed in security.txt. Include affected URL, reproducible steps and impact, but do not include unrelated personal data or publish a working exploit.
Safe-harbor expectations¶
Use only accounts and data you control, stop when access crosses an authorization boundary, avoid disruption and allow reasonable time for remediation. MATERRA will acknowledge good-faith reports and coordinate disclosure; this policy does not authorize unlawful access.