Security

Vulnerability disclosure policy

We welcome reports of security weaknesses. This policy explains what is in scope, how to test safely, and what to expect after you report.

Effective 6 August 2026 · maintained by the app owner

How to report

Send a report to the app owner's security contact listed at /.well-known/security.txt. Include the affected URL, reproduction steps, impact, and any proof-of-concept. Please do not disclose publicly before we have responded.

In scope

  • The marketing site and the authenticated application
  • Public API endpoints under /api/public
  • Tenant isolation, authorization, and export-integrity controls

Out of scope

  • Denial-of-service, volumetric or brute-force testing
  • Social engineering of staff, customers or their employees
  • Reports from automated scanners without a demonstrated impact
  • Missing hardening headers with no exploitable consequence
  • Findings in third-party platform infrastructure (report those upstream)

Testing rules and safe harbour

Test only against accounts and tenants you own. Never access, modify, exfiltrate or retain another party's employment records; stop at the first proof of access and report it. Where you follow this policy in good faith, we will not pursue legal action and will treat your research as authorized.

Our response

  • Acknowledgment within 3 business days
  • Initial triage and severity assessment within 10 business days
  • Remediation timeline shared once triage completes, with progress updates
  • Credit in release notes on request, once the fix is deployed

Customer notification

Where a confirmed vulnerability affected customer content, affected controllers are notified without undue delay through the incident response workflow so they can meet their own notification deadlines.