Skip to content

Legal

Responsible disclosure

How to report a vulnerability, and what we commit to in return.

Last updated

If you believe you have found a vulnerability in SafeLoop, report it to security@safeloop.com. Our machine-readable policy is published at /.well-known/security.txt.

What we commit to

  • Acknowledgement within one business day.
  • A triage decision within five business days.
  • Progress updates until the issue is closed.
  • Credit in our advisory if you would like to be credited.
  • No legal action, and no support for legal action by others, against research conducted in good faith under this policy.

What we ask

  • Test only against your own tenant, or one we provision for you.
  • Do not access, modify or exfiltrate other customers' data.
  • Do not degrade the service — no denial of service, no load testing without agreement.
  • Do not use social engineering against our staff, our customers or our subprocessors.
  • Give us reasonable time to remediate before publishing.

Out of scope

  • Findings from automated scanners without a demonstrated impact.
  • Missing security headers with no exploitable consequence.
  • Reports about the deliberate design of simulated phishing content.
  • Social engineering, physical access and third-party services we do not control.

Questions about this document? Email legal@safeloop.com or contact us.

See your human risk in 20 minutes

Book a demo and we’ll run a sample campaign against a test group.