Report security
clearly.

If you believe you found a vulnerability in a Prism Labs public system, report it privately so we can investigate and protect people.

How to report

Email [email protected] with a concise description, affected host or component, reproduction steps, potential impact, and supporting material that excludes unrelated personal data. Do not send credentials or sensitive customer information in ordinary email.

Good-faith research

Use only accounts, communities, machines, and data you own or are explicitly authorized to test. Avoid privacy violations, data destruction, service degradation, persistence, social engineering, physical testing, denial of service, automated high-volume scanning, and access to another person’s content.

What to expect

We aim to acknowledge a credible report within five business days, assess severity, keep the reporter informed when practical, and coordinate disclosure after a fix. These are early-stage targets, not contractual service levels.

Safe-harbor intent

When research follows this policy, is lawful, avoids harm, and is reported promptly, Prism Labs does not intend to pursue legal action solely for that good-faith research. This cannot authorize conduct prohibited by third parties or law.

Other requests

General support, feature requests, lost-account issues, spam, and scanner output without reproducible impact should go to [email protected].

Machine-readable policy

Security contact information is also published at /.well-known/security.txt.