Report a suspected security or privacy issue.

Use coordinated disclosure, avoid candidate data, and give enough reproducible detail for the issue to be reviewed safely.

What to include.

Affected surface

The URL, route, or feature where the issue appears.

Reproduction

A concise sequence of steps using fabricated or non-sensitive test data.

Observed impact

What an attacker or unauthorized person could access, change, or disrupt.

Supporting detail

Relevant headers, timestamps, request IDs, screenshots, or proof of concept with secrets removed.

Safe testing boundaries.

Do not access another person's data, upload a real candidate resume for testing, perform denial-of-service activity, send malware, use social engineering, publish a vulnerability before coordination, or retain information beyond what is necessary to report the issue.

Stop testing and report promptly if you encounter personal data, credentials, service secrets, or access to another account or subscription.

How reports are handled.

Role Evidence will aim to acknowledge a complete report, assess severity and reproducibility, request clarification when needed, and coordinate remediation and disclosure timing. Response timing can vary with complexity and operational capacity.

There is no public bug bounty program, and this page does not promise payment. Good-faith research that follows these boundaries will be considered in the response process.

Send the report.

Use the security category in the contact form. Do not attach candidate or customer content.