SINK welcomes good-faith reports that help protect viewers, contributors, screening teams, and confidential projects. A formal bug-bounty program is not currently offered.
What to send
A clear description of the behavior and possible impact
The affected SINK surface, URL, app version, or extension version
Minimal reproducible steps using your own account and data
Relevant timestamps, request identifiers, and sanitized screenshots
A safe way to contact you for follow-up
Please do not
Access, change, download, or delete another person's data
Test against confidential screeners, invitations, or production assets
Use social engineering, denial of service, spam, malware, or physical attacks
Send passwords, session tokens, private keys, full media files, or unnecessary personal data by email
Assume this page grants authorization that applicable law or an account agreement does not grant
Reporting channel
Until a dedicated encrypted security intake is published, send a minimal initial report to support@sink.chat with “Security report” in the subject. Do not attach secrets or confidential media. We will arrange a safer transfer method if sensitive evidence is genuinely required.