Security

Vulnerability Disclosure Policy

Last updated September 5, 2026. This English version is provided for convenience; the Indonesian version governs if there is a difference in meaning.

Report responsibly

Send security reports to [email protected] with a clear description, affected URL or component, safe reproduction steps, impact, and any proof of concept that does not expose personal data.

Safe testing

Do not disrupt the service, access accounts or infrastructure, exfiltrate data, run destructive tests, or publicly disclose an issue before allowing reasonable time for review and remediation. Stop immediately if you encounter sensitive data.

What happens next

We review the report, may request safe clarification, validate impact, and prioritize a fix according to severity and feasibility. Structured contact information is also available at /.well-known/security.txt.