Report a vulnerability privately

If you find something wrong, tell us before telling the world. Use the private channel and share only what is needed.

Report sensitive problems without publishing them

Please do not open a public issue for a suspected vulnerability, exposed file, credential, private record, or unsafe deployment condition.

Until EthicsNet publishes a dedicated private security address, use Nell Watson’s contact page and begin with “EthicsNet security report”. Include the affected URL or repository, likely impact, safe reproduction steps, and a contact route.

Research boundaries

Good-faith, non-destructive research intended to improve safety is welcome. Avoid disrupting the service, invading privacy, using social engineering, accessing other people’s data, or going beyond the minimum needed to demonstrate an issue.

Scope

This channel covers ethicsnet.org and its website repository. Linked projects may publish their own security policies, which take precedence for those projects.

Sensitive material

Do not include live credentials, personal data, or destructive proof in the first message. EthicsNet will coordinate a safer transfer method if needed.