Report a Security Problem

If you have found a vulnerability in R.A.C.E., this form records it with a reference immediately. You do not need an account, and you do not have to tell us who you are.

What we do and do not promise

We record every report and a person reviews it. We do not publish a response deadline, a disclosure timetable or a bug bounty, and this page does not create one. We would rather say that plainly than imply terms we have not agreed.

This form is for security problems. To report abusive content or a rule breach, use the report control on the content itself. For a copyright claim, use the copyright notice form.

A URL, an API endpoint, or the name of a screen.

We record what you tell us. We are not asking you to agree to an embargo — we have not published one.

Both fields below are optional. You can report anonymously. The only thing you lose by leaving them blank is our ability to reply.

You may also write to [email protected]. Email is read by a person rather than recorded automatically, so this form is the route that produces a dated record and a reference immediately.

Section 7 of the Privacy Policy describes the measures this reporting channel exists to backstop.