Security Vulnerability Policy
We take the security of our services, users, and data seriously. If you have discovered any security vulnerabilities or have concerns regarding our software systems, we encourage you to let us know immediately so we can address them.
Our Core Commitments
If you conduct vulnerability research and disclose security bugs to us in good faith, we commit to the following principles:
- ✔ Timely Response: We will acknowledge your report within 48 hours and work with you to understand and mitigate the vulnerability.
- ✔ No Legal Action: If you comply with this policy and act in good faith, we will not initiate legal action against you.
- ✔ Validation & Patches: We will investigate your findings diligently and keep you updated as we implement corrective updates.
Submission Guidelines
To help us triage and patch your reported issue as quickly as possible, please provide a comprehensive and reproducible proof of concept:
What is Out of Scope?
We do not accept reports for issues that cause minor business inconveniences, basic non-exploitable cosmetic errors, or reports generated solely by robotic static tools with no verification. Please refrain from the following activities:
- ✕ Denial of Service (DoS) attacks or brute-force tests.
- ✕ Social engineering, phishing, or physical attacks against our support structures or hosting physical centers.
- ✕ Accessing, modifying, or deleting other users' information or tenant workspaces.
Ready to submit a report?
If you have identified an issue conforming to our guidelines, please send details to our primary vulnerability mailbox.