Derive
Security & abuse

Report abuse or a vulnerability

Derive hosts pages and documents published by its users, including on subdomains of derive.page, our dedicated user-content domain. If something hosted there — or anywhere on Derive — is being used for phishing, malware, impersonation, or other abuse, we want to know.

Report abusive content

abuse@derive.to

Send the full URL of the page and a short description of the problem. Reports are read by a human; confirmed phishing and malware are removed on an expedited basis.

Report a security vulnerability

security@derive.to

For vulnerabilities in Derive itself — the app, the API, or the hosting of user content. Please give us a reasonable window to remediate before public disclosure. The server is source available; issues in the code are also welcome there.