Trust Center Open a Request

Responsible disclosure policy

How to report a vulnerability to us, what is in scope, and what we promise in return.

PolicyPublic

We welcome reports from security researchers. If you believe you have found a vulnerability in Cases or any css.io service, email [email protected] with the steps to reproduce it.

Our commitments

  • We acknowledge your report within one business day.
  • We keep you informed as we investigate and fix the issue.
  • We will not take legal action against research carried out in good faith under this policy.
  • With your permission, we credit you once the issue is resolved.

Please

  • Do not access, modify or delete data that is not yours.
  • Do not degrade the service (no denial-of-service or load testing).
  • Do not use social engineering or physical attacks.
  • Give us reasonable time to fix the issue before disclosing it.

Request documents

Choose the documents your review needs and tell us who you are. We reply within one business day.

Documents

Questions? [email protected]