ความเป็นส่วนตัว ข้อมูล และความปลอดภัย
Security, Account Protection and Vulnerability Reporting Policy
Security expectations, prohibited abuse and a responsible path for reporting vulnerabilities.
อัปเดตล่าสุด: 2 กันยายน 2569
กลุ่มเป้าหมาย: All visitors and users
สำคัญ: เอกสารนี้เป็นคำแถลงนโยบายผลิตภัณฑ์และการควบคุมความเสี่ยง ไม่ใช่คำแนะนำทางกฎหมายสำหรับบุคคล ไม่ได้เป็นการสละสิทธิที่ไม่อาจสละได้ และไม่ควรตีความว่ากฎหมายทุกฉบับที่ระบุไว้ใช้บังคับในทุกเขตอำนาจศาล
Security baseline
- Use least privilege, secret separation, rate limits and repository-enforced infrastructure boundaries.
- Do not expose internal state services or credentials publicly.
- Preserve auditability for security-relevant changes and incidents.
Research and reporting
Good-faith vulnerability reports should describe the issue and reproduction safely without accessing unnecessary user data, persistence, extortion, destructive testing, credential harvesting or disruption. Authorization for security testing is not implied by this policy.