Legal
Responsible disclosure
How to report a vulnerability, and what we commit to in return.
Last updated
If you believe you have found a vulnerability in SafeLoop, report it to security@safeloop.com. Our machine-readable policy is published at /.well-known/security.txt.
What we commit to
- Acknowledgement within one business day.
- A triage decision within five business days.
- Progress updates until the issue is closed.
- Credit in our advisory if you would like to be credited.
- No legal action, and no support for legal action by others, against research conducted in good faith under this policy.
What we ask
- Test only against your own tenant, or one we provision for you.
- Do not access, modify or exfiltrate other customers' data.
- Do not degrade the service — no denial of service, no load testing without agreement.
- Do not use social engineering against our staff, our customers or our subprocessors.
- Give us reasonable time to remediate before publishing.
Out of scope
- Findings from automated scanners without a demonstrated impact.
- Missing security headers with no exploitable consequence.
- Reports about the deliberate design of simulated phishing content.
- Social engineering, physical access and third-party services we do not control.
Questions about this document? Email legal@safeloop.com or contact us.