legal
Security disclosure
How to report a flaw, what happens next, and what we undertake not to do to anyone who reports one in good faith.
Written from the system, not from a template. Every statement here describes what the software actually does — the region, the sub-processors, what is collected, what is retained, what leaves the EEA. It is a description of a system rather than legal advice, and it is published rather than sent after a call. If your counsel needs redlines, or your own paper, that is a conversation and not a problem.
▸Contents — 7 clauses
1How to report#
2What happens next#
- Within three working days you get an acknowledgement from a person, not an autoresponder.
- Within ten working days you get an assessment: whether it is reproduced, roughly how serious we think it is, and what we intend to do.
- While we are fixing it you get an update at least every two weeks, or sooner if something changes.
- When it is fixed you are told, and asked to confirm the fix if you want to.
If we decide not to fix something, you will be told that and told why, rather than hearing nothing. A decision you disagree with is a better outcome than silence.
These are targets rather than a contractual service level. They are what we intend to do and what you should hold us to; a contractual commitment on response times is agreed in writing with the customers who need one.
3What is in scope#
4What we ask you to do#
- Test only against workspaces and accounts you created. Do not access, modify or retain anybody else's data — if you do reach it, stop immediately, say so in the report, and delete what you retrieved.
- Do not degrade the service. No load testing, no denial of service, no spam of the invite form or the sign-in flow, and no social engineering of anyone.
- Do not use a finding for anything other than demonstrating it, and do not hold it for payment.
- Give us ninety days before publishing, or less if we have fixed it sooner and agreed. If we go quiet on you for more than thirty days, treat that as our failure and publish.
- Comply with the law. Nothing here authorises anything unlawful.
5Safe harbour#
6Recognition, and money#
There is no bug bounty programme and no payment. If you would like credit, you will get it by name or handle wherever the fix is described, and you can decline. We will not make credit conditional on you signing anything or on you staying quiet, which is the practice that has made a lot of vendor disclosure programmes worthless.
7Telling customers#
Where a reported vulnerability affected personal data we process for a customer, that customer is notified without undue delay under clause 9 of the data processing agreement, in stages if that is faster than waiting for one complete account.
Vulnerability disclosure policy, version 0.2, effective 29 July 2026. Every agreement, and who you are contracting with, on the legal index.