Responsible disclosure policy
How to report a vulnerability to us, what is in scope, and what we promise in return.
We welcome reports from security researchers. If you believe you have found a vulnerability in Cases or any css.io service, email [email protected] with the steps to reproduce it.
Our commitments
- We acknowledge your report within one business day.
- We keep you informed as we investigate and fix the issue.
- We will not take legal action against research carried out in good faith under this policy.
- With your permission, we credit you once the issue is resolved.
Please
- Do not access, modify or delete data that is not yours.
- Do not degrade the service (no denial-of-service or load testing).
- Do not use social engineering or physical attacks.
- Give us reasonable time to fix the issue before disclosing it.