Send security reports privately to [email protected]. Do not open a public issue containing an unpatched vulnerability, account data, token, private key, server route, or personal media information.

Include the affected Portico component and version, the expected and observed result, the smallest reproducible steps, and the security impact. State whether the issue has been tested against a server, hosted account, client, or documentation site.

Use a test account and non-sensitive media wherever possible. Remove secrets from logs and screenshots before attaching them.

Do not access another person’s server, account, or data while testing a report.