01
How to report
Email [email protected] with the affected address or component, impact, reproduction steps, date observed, and a minimal safe proof of concept. Do not send credentials, unrelated personal data, or destructive payloads. A dedicated monitored mailbox and encrypted follow-up path must be verified before launch.
02
Permitted good-faith behavior
Use only accounts and data you own or have explicit written authorization to test. Keep requests low volume, stop when sensitive information appears, preserve evidence safely, report promptly, and allow reasonable remediation time before disclosure.
03
Prohibited testing
Do not access another customer’s data; use social engineering; send spam; test physical security; perform denial-of-service or resource-exhaustion activity; upload malware; modify or destroy records; disrupt production; or retain data obtained accidentally.
04
What to expect
We aim to acknowledge credible reports, establish a secure communication path, assess severity, contain risk, and share progress when practical. Internal acknowledgment and remediation targets must be staffed and approved before they are published as commitments.
05
Authorization and safe harbor
This draft does not authorize conduct prohibited by law, the Terms, or provider rules and does not create a bug bounty. Any legal safe-harbor assurance requires explicit counsel approval and clearly defined scope.
06
Disclosure and recognition
Coordinate public disclosure with Batch Scale so customers can be protected. Recognition or compensation, if any, is discretionary unless a separate written program states otherwise.