Security / Engineering practice
Security claims should match the system that actually exists.
Authentication, local data, permissions and dependency risk are engineering concerns. Product-specific behavior is documented per app rather than generalized across the portfolio.
Identity & access
Authentication and authorization are designed around the runtime, redirect model and actual session boundaries.
Sensitive local data
Protection choices should reflect the sensitivity, operating-system capabilities and recovery requirements.
Permissions & device access
Mobile permissions should match real product capabilities and not be broader than the supported workflow requires.
Dependencies & delivery
Framework, library and build dependencies are part of application risk and long-term maintainability.
Responsible disclosure
Found a security issue?
Please avoid publicly disclosing an unresolved vulnerability before there has been a reasonable opportunity to investigate it.
Send the affected product/page, reproduction steps and impact. Do not include unnecessary sensitive user data.
Report a security issueThis page describes engineering principles and website reporting guidance. It is not a certification, penetration-test report or guarantee that any software is free from vulnerabilities.