Trust / security
Report security
clearly.
If you believe you found a vulnerability in a Prism Labs public system, report it privately so we can investigate and protect people.
How to report
Email [email protected] with a concise description, affected host or component, reproduction steps, potential impact, and supporting material that excludes unrelated personal data. Do not send credentials or sensitive customer information in ordinary email.
Good-faith research
Use only accounts, communities, machines, and data you own or are explicitly authorized to test. Avoid privacy violations, data destruction, service degradation, persistence, social engineering, physical testing, denial of service, automated high-volume scanning, and access to another person’s content.
What to expect
We aim to acknowledge a credible report within five business days, assess severity, keep the reporter informed when practical, and coordinate disclosure after a fix. These are early-stage targets, not contractual service levels.
Safe-harbor intent
When research follows this policy, is lawful, avoids harm, and is reported promptly, Prism Labs does not intend to pursue legal action solely for that good-faith research. This cannot authorize conduct prohibited by third parties or law.
Other requests
General support, feature requests, lost-account issues, spam, and scanner output without reproducible impact should go to [email protected].
Machine-readable policy
Security contact information is also published at /.well-known/security.txt.
Private vulnerability reports
[email protected] ↗