Send a message
This route is for people. Browser agents may prepare the form, but a person must review it and complete Cloudflare Turnstile. Software agents should use the MCP endpoint or Audit API instead of scraping the interface.
Please do not send passwords, private keys, report access tokens, confidential customer data, or hostile submission payloads.
Security reports
Use the contact and encryption guidance in security.txt. Good-faith reports should identify the affected URL, impact, reproducible steps, and a safe way to coordinate.
Privacy and deletion
A report access token can delete its audit through the API. For broader access, correction, or deletion requests, choose the privacy topic above and include enough non-sensitive information to locate the record.