# I found a security vulnerability. How do I report it? Email privacynotes@lifetimelabs.dev. The same address is published in our PGP-signed [security.txt](https://privacynotes.app/.well-known/security.txt), so you can confirm it is genuine before you write, and our [public key](https://privacynotes.app/.well-known/pgp-key.txt) is there if you would rather encrypt the report. We reply, and where a fix needs coordinating we agree the disclosure timing with you before anything goes public. Reports reach the people who wrote the code directly, and a reporter who wants credit gets it. Test against the demo at try.privacynotes.app or a throwaway account, never against somebody else's notes. ## Read the source - SECURITY.md: Reporting a vulnerability -> https://privacynotes.app/docs/security.md (source: https://github.com/LifetimeLabsDev/PrivacyNotes.app/blob/main/SECURITY.md#reporting-a-vulnerability) --- Source: https://privacynotes.app/help/report-vulnerability