Security & vulnerability disclosure
We welcome reports from security researchers. Send findings to awaran2026@gmail.com with the subject 'Security report', including the affected URL, reproduction steps and impact. We acknowledge valid reports within 5 working days, assess each case on its merits and can credit you once an issue is fixed. In scope: our websites, the browser extension and the public Developer API. Out of scope: denial of service, social engineering and automated scanner output without a proof of concept.