Security disclosure

Disclose a vulnerability without publishing exploit detail.

Use this protected boundary for a vulnerability or security weakness. Do not test beyond your own authorization.

Review audience

Commander security response

This destination writes only to its named database boundary. It does not forward the submission into Contact or the general contribution queue.

Include the minimum reproduction detail needed for authorized review. Never include credentials, session values, or data taken from another person.

Email is stored only inside this boundary and is never included in public criticism or notification email.

Completing the security check… If it remains here, reload this page; your browser may be blocking the check.

Wrong boundary? Return to all four accountability routes.

Name the affected surface.

Identify the product, route, component, or configuration without publishing the weakness elsewhere.

Describe the minimum safe reproduction.

Include enough detail for authorized validation but no credentials or another person’s data.

Stop at your authorization boundary.

Do not escalate access, persist, exfiltrate, disrupt, or test beyond what you own or were asked to test.

Do not use this form to request authorization to test. Stop testing and use the minimum disclosure necessary for defensive review.

Security disclosure