We take reports seriously and we don't sue researchers.
Report privately through GitHub Security Advisories ("Report a vulnerability" on the repo's Security tab). Include steps to reproduce and, if you can, a proof of concept.
The desktop binary, the CLI, this website, and the Hosted relay are all in scope. The fact that a MITM proxy can read TLS is by design, not a vulnerability — see the security model.
Good-faith research that follows this policy is authorized. We won't pursue legal action and we'll help if anyone else tries to.