# Reporting a security issue If you believe you have found a security problem in a Capable app, tell us directly rather than filing it as a support ticket or posting it publicly. We would rather hear about a false alarm than miss a real one. --- ## How to report * Contact us through the Capable service desk, marking the request as a security issue. * Include what you found, how to reproduce it, and what you think the impact is. * Tell us if you have shared it anywhere else, and give us a chance to fix it before you do. --- ## What happens next | **Stage** | **What we do** | | --------------- | -------------------------------------------------------------------- | | Acknowledgement | We confirm we have it, and who is looking at it | | Assessment | We reproduce it and work out the real impact | | Fix | We ship a fix, and tell you when it is out | | Disclosure | If customers were affected, it gets an incident report on this space | ⚠️ **Please do not test against another customer's site.** Use your own instance or a free developer instance. Testing against somebody else's data is not research. --- ## A few things worth knowing * A vulnerability that affected customers gets a public incident report, the same as an outage. * We will tell you if something you reported turns out to be intended behaviour, and why. * Reports about the Atlassian platform itself are better raised with Atlassian, but tell us too and we will help. --- ## Related [How Capable apps are builtEvery Capable app for Confluence runs on Atlassian Forge, which decides most of ](https://help.gocapable.com/trust/how-capable-apps-are-built.html) [Where our services runWhich parts of Capable run where, and how to remove the parts that leave your te](https://help.gocapable.com/trust/where-our-services-run.html) [Security and privacyThe rest of this section.](https://help.gocapable.com/trust/security-and-privacy.html) --- _Tell us first. We would rather know._