Coordinated disclosure

Report a security issue

Tell us privately. We will fix it and tell you when we did.

If you found a way to reach data that is not yours, to act as somebody else, or to take the service down, send it here rather than posting it. You get a reference number back immediately and a human reply, and we will tell you what we found even when the answer is that it was not a bug.

What we want

A report we can reproduce

The URL or endpoint, the account or role you were using, the exact steps, and what you saw that you should not have seen. A short screen recording beats a long description. If it took a script, send the script.

What we do

Triage, then a real answer

We acknowledge inside one business day, tell you whether we reproduced it inside five, and give you a fix date once we have one. If we decide it is not a vulnerability, we say why instead of going quiet.

Safe harbor

Report in good faith and we will not come after you

We will not pursue legal action over research that stays inside the rules below, and we will say so in writing if you need it. We do not run a paid bounty program today, so please do not ask for a payout as a condition of telling us.

Rules of engagement

Test against your own account, and stop when you have proved it

The service places real phone calls and holds real contact data belonging to small businesses. A test that harms them is not research. Everything below is a line we ask you not to cross, and staying inside them is what the safe harbor is conditioned on.

  • Use an account you control. Do not touch another customer's data
  • Stop at proof. Do not read, copy, keep, or publish what you reached
  • No load testing, no denial of service, no automated scanning that places calls
  • No social engineering of our staff, our customers, or our carriers
  • Give us a fix window before you write it up publicly

If you believe a real account has already been broken into, say so in the first line of the report. That moves it to the front of the queue ahead of everything else.

Acknowledge 1 DAY
A human confirms we have it, with your reference number
Reproduce 5 DAYS
We tell you whether we could reproduce it, and what we saw
Fix date ON TRIAGE
Severity drives the date. We give you the date, not a maybe
Bounty NONE YET
No paid program today. We will credit you if you want the credit
Out of scope

Things we already know about

Sending these does not get a fix date, though it still gets an answer.

Scanner output with no impact

A missing header, a cookie flag, a TLS suite rating, or a version banner, with nothing behind it that a person can actually do. Show us the exploit and it becomes in scope.

Reports about a call you received

That is a different problem with a different process. Send it through the abuse page so it reaches the team that can trace the number and act on the account behind it.

Security report

Send it here

Put the steps in the message. Do not attach data belonging to another account.

We reply by email, normally within one business day. You get a reference number the moment it lands.

Version 1.0.91