Skip to content
Müşavir

Responsible Disclosure

Found a vulnerability? Tell us first

We value reports from security researchers. We do not pursue legal action for research done in good faith and in line with this policy. Below we explain which systems are in scope, how to report, and when you can expect to hear from us.

Report a vulnerability

How to report

  1. 1

    Record the finding

    Note the affected address, steps to reproduce, the possible impact and, if available, a screenshot or sample request.

  2. 2

    Send it to us

    Choose 'Security report' on our contact page. The current reporting channel is also in the /.well-known/security.txt file on the site.

  3. 3

    Wait for our reply

    We confirm receipt, assess the report and keep you updated while we fix it.

  4. 4

    Disclose together

    After the fix ships, we can agree together on when the finding is made public, if you wish.

Response time targets

Times are targets; they may vary with the complexity of the finding, and we will tell you if there is a delay.

StageTarget
Acknowledgement3 business days
Initial assessment and severity10 business days
Fix for a critical vulnerability30 days
Fix for other vulnerabilities90 days
Coordinated disclosureAfter the fix, on a date agreed together

Scope

In scope:

  • The panel application and its API
  • The marketing site
  • Pages opened through shareable links: proposal page, reconciliation approval page, customer statement
  • Authentication, session management and data isolation between companies

Out of scope:

  • Denial of service (DoS, DDoS) and load testing
  • Social engineering, phishing and physical access attempts
  • Third-party services we do not operate (our subprocessors and services tenants connect); report those to the provider
  • Findings without demonstrated impact, such as a missing security header, SPF or DMARC settings, or clickjacking on pages without a session

What not to do

  • Access, modify, delete or exfiltrate data belonging to other users or companies
  • Run automated scans or heavy request volumes that degrade the service
  • Leave persistent access in the system (backdoor, user account, scheduled job)
  • Disclose the finding publicly or to third parties before a fix ships
  • Use the finding to demand payment

If you come across personal data during research, stop, do not keep the data and mention it in your report.

Good-faith research safe harbor

We consider research carried out in good faith and in line with this policy to be authorized, we will not start legal proceedings against you, and if a third party does, we will state that you followed this policy. If you are unsure whether something is in scope, ask through the contact page before testing.

security.txt

Our security reporting channel and the address of this policy are published in the /.well-known/security.txt file in RFC 9116 format.

Frequently asked questions

Do you run a bug bounty?

We do not have a paid bounty program today. For valid, in-scope findings, and with your permission, we credit you on our thanks list.

When will you not take legal action?

As long as you follow the rules in this policy, do not access other users' data (or stop and report immediately if access occurred), do not disrupt the service and do not share the finding before it is fixed, we treat your research as authorized.

Can I report by email?

To report, choose 'Security report' on our contact page; the current channel is also in the security.txt file. If your report must include personal data, keep it to the minimum.

Can I test on my own company account?

Yes, only on trial accounts you created yourself and with your own data. If you find a flaw that exposes another company's data, stop at the minimum access needed as proof and report it.

Related

Send your security report

Choose 'Security report' on our contact page to send your finding; we aim to confirm receipt within 3 business days.

Report a vulnerability