Include in the first report
- A concise description of the suspected issue, the affected Rootsly URL or feature and the security impact you believe is possible.
- The date and UTC time observed, browser or client context and minimal numbered steps using your own account or synthetic data.
- Whether you stopped after seeing another person's data, cross-tenant behaviour, a secret or an unexpected external effect.
- A safe opaque evidence reference if one exists; wait for a protected exchange route before sending screenshots, traces or other sensitive material.
- A contact method Rootsly can use for clarification and whether you want public acknowledgement considered after remediation.
Need to share sensitive evidence? Ask for a protected exchange route first. Do not place evidence in a public file host or a normal support ticket.