Use the subject line [SECURITY] ProtoCall report.
What to include
- Affected product, version and operating system.
- A concise description of the issue and its likely impact.
- Safe reproduction steps using a lab target where possible.
- Whether you believe the issue is already being exploited.
- Your preferred contact details and any disclosure deadline you propose.
Protect sensitive evidence
Do not email passwords, private keys, access tokens, personal data, confidential controller programs or an unredacted production capture. First send a summary and request a suitable transfer method. Do not publish an unresolved vulnerability or use it to access data, disrupt operations or move beyond the minimum proof required.
What to expect
The publisher aims to acknowledge a credible report within five working days, assess severity and affected versions, and coordinate a proportionate fix and disclosure plan. This is not a paid bug-bounty programme, and a response time is not guaranteed for incomplete, abusive or unrelated submissions.
Good-faith research
Research must be lawful, limited to systems you own or are authorised to test, and designed to avoid harm. The publisher will not initiate legal action merely because a researcher reports a genuine issue in good faith while respecting those limits, but cannot authorise testing of third-party systems or waive another party's rights.