Security
Report a security concern privately and responsibly.
This page explains how to report a concern and makes clear that unauthorized testing is not permitted.
Effective: July 22, 2026 · Last updated: July 22, 2026
Responsible security reporting
If you believe you found a security problem, report it privately. Do not exploit it, access other people’s information, disrupt the Site, or publicly disclose details before Riley has had a reasonable opportunity to investigate.
How to report
Use the Contact page and choose the security or legal category. Include the affected URL, a concise description, reproduction steps that do not expose data, and your contact information.
No authorization to test
This policy does not authorize penetration testing, vulnerability scanning, automated probing, denial-of-service activity, social engineering, credential testing, access-control bypass, data access, malware, or any activity that violates law or the Terms of Use. Obtain written permission before any active testing.
Please avoid
- Accessing, changing, deleting, or downloading data that is not yours.
- Testing contact or newsletter forms with high-volume or malicious submissions.
- Attempting to obtain passwords, tokens, private repositories, or service-provider access.
- Publishing technical details before remediation.
Response
Riley may acknowledge, investigate, request information, contact providers, remediate, decline, or refer a report to authorities or counsel. No bounty or compensation is promised unless agreed in writing before the report.