Help us correct unsafe conditions safely

Security reports should protect users, researchers, maintainers, and the integrity of the evidence. Use a private route and disclose only what is necessary.

Report sensitive problems without publishing them

Please do not open a public issue for a suspected vulnerability, exposed file, credential, private record, or unsafe deployment condition.

Until EthicsNet publishes a dedicated private security address, use Nell Watson's contact page and begin with “EthicsNet security report”. Include the affected URL or repository, likely impact, safe reproduction steps, and a contact route.

Research boundaries

Good-faith, non-destructive research intended to improve safety is welcome. Avoid service disruption, privacy invasion, social engineering, accessing other people's data, or going beyond the minimum needed to demonstrate an issue.

Scope

This route covers ethicsnet.org and its website repository. Linked projects may publish their own security policy, which takes precedence for that project.

Sensitive material

Do not include live credentials, personal data, or destructive proof in the first message. EthicsNet can coordinate a safer transfer method if needed.