Include reproducible, minimal evidence
Describe the affected URL or component, prerequisites, safe reproduction steps, observed result and expected security boundary. Use synthetic data wherever possible.
Do not perform destructive testing
Do not send or delete real email, access another person's account, expose secrets, degrade availability, run automated high-volume scans or retain data that is not yours.
Use the published policy endpoint
The canonical security contact and policy are also published at /.well-known/security.txt for automated discovery.