Security and Vulnerability Reporting
Effective date: October 11, 2026
Use this channel to report suspected security vulnerabilities in Reconstruct. We do not offer a paid bug-bounty program.
Report a suspected vulnerability in Reconstruct to [email protected]. Include the affected Reconstruct URL or component, a short description, the impact and the smallest steps that reproduce it. Remove personal data and secrets. Ask us for a secure channel before you send sensitive evidence.
Test only accounts and data you control. Do not access another person's information, disrupt the service, run denial-of-service or social-engineering attacks, or test a third-party system through Reconstruct. Stop and contact us if you unexpectedly find someone else's data. Our analysis of a third-party application does not give you permission to test that application's security.
We review reports and work with reporters on remediation and coordinated disclosure. Response times vary depending on the report.
Account and support questions go to [email protected]. Privacy requests go to [email protected]. Content complaints follow our Copyright Policy.