Security / Engineering practice

Security claims should match the system that actually exists.

Authentication, local data, permissions and dependency risk are engineering concerns. Product-specific behavior is documented per app rather than generalized across the portfolio.

01

Identity & access

Authentication and authorization are designed around the runtime, redirect model and actual session boundaries.

02

Sensitive local data

Protection choices should reflect the sensitivity, operating-system capabilities and recovery requirements.

03

Permissions & device access

Mobile permissions should match real product capabilities and not be broader than the supported workflow requires.

04

Dependencies & delivery

Framework, library and build dependencies are part of application risk and long-term maintainability.

Responsible disclosure

Found a security issue?

Please avoid publicly disclosing an unresolved vulnerability before there has been a reasonable opportunity to investigate it.

Send the affected product/page, reproduction steps and impact. Do not include unnecessary sensitive user data.

Report a security issue

This page describes engineering principles and website reporting guidance. It is not a certification, penetration-test report or guarantee that any software is free from vulnerabilities.