Reporting a vulnerability
Email the address at the bottom of this page with “Security” in the subject line. Please include enough detail for us to reproduce the issue: the URL or endpoint, the steps you took, and what you observed.
We will acknowledge your report within five business days, keep you updated as we investigate, and tell you when it is resolved. We are a small practice, not a security team, so please be patient with our timelines, but we will not ignore you.