Security and Reporting

Responsible Disclosure

A safe channel for reporting suspected vulnerabilities, abuse paths, or platform security weaknesses.

Version
1.0
Effective
May 23, 2026
Reviewed
May 23, 2026
Status
Published

The Responsible Disclosure policy explains how researchers and users can report suspected vulnerabilities safely. Reports should include affected systems, steps to reproduce, impact, and contact information. Reporters must avoid accessing private data, disrupting services, or publicly disclosing findings before GOES has reviewed them.

Related Policies

Security and Reporting

Security Policy

Security expectations for accounts, systems, data, vendors, incidents, and responsible operation of GOES services.

View policy