Report a vulnerability
Use the security form in the Support Centre or email [email protected] with a clear security subject line. Open form
Include:
- the affected URL or component;
- the type of issue;
- safe reproduction steps;
- the potential impact;
- browser or environment information; and
- a minimal proof that does not expose other people’s data.
Do not include
Do not send passwords, authentication codes, private keys, active malware, full database dumps, another person’s private information or unnecessary exploit material by ordinary email.
Private evidence should be uploaded only through the protected case system.
Good-faith research rules
To reduce harm, do not:
- access, change, download or delete data that is not yours;
- maintain persistence in an account or system;
- perform denial-of-service, load or resource-exhaustion testing;
- run broad automated scans that degrade service;
- send spam, phishing or social-engineering messages;
- test physical security or third-party providers without permission;
- publicly disclose an unresolved issue before MatchTide has a reasonable opportunity to investigate; or
- demand payment or threaten disclosure.
Stop testing after obtaining the minimum evidence needed to explain the issue.
What MatchTide will do
MatchTide may acknowledge the report, ask questions, reproduce the issue, record remediation and provide a status update. Response and remediation time depends on severity, complexity and available resources.
MatchTide does not currently promise a bug bounty or payment.
Account-security incidents
If you believe your account is compromised, change your password where possible, end active sessions and contact [email protected]. Do not post the incident publicly in comments.
Urgent danger or crime
MatchTide is not an emergency service. Contact the appropriate emergency or law-enforcement authority where immediate harm is likely.
security.txt
MatchTide publishes a machine-readable security contact at /.well-known/security.txt. The file points to this Policy and [email protected] and does not create a broader permission to test.