Quyền riêng tư, dữ liệu & bảo mật
Security, Account Protection and Vulnerability Reporting Policy
Security expectations, prohibited abuse and a responsible path for reporting vulnerabilities.
Cập nhật lần cuối: 2 tháng 9, 2026
Đối tượng: All visitors and users
Quan trọng: Văn bản này là tuyên bố về chính sách sản phẩm và kiểm soát rủi ro, không phải tư vấn pháp lý cá nhân. Văn bản không làm mất các quyền không thể từ bỏ và không nên được hiểu là khẳng định rằng mọi luật được liệt kê đều áp dụng ở mọi khu vực pháp lý.
Security baseline
- Use least privilege, secret separation, rate limits and repository-enforced infrastructure boundaries.
- Do not expose internal state services or credentials publicly.
- Preserve auditability for security-relevant changes and incidents.
Research and reporting
Good-faith vulnerability reports should describe the issue and reproduction safely without accessing unnecessary user data, persistence, extortion, destructive testing, credential harvesting or disruption. Authorization for security testing is not implied by this policy.