Security
Report a security vulnerability
If you believe you have found a security problem in Disclosure, tell us here. We read every report and reply to each one.
What we ask
- Give us the detail privately first, and reasonable time to fix it before you publish anything.
- Test only against your own account. Do not read, change or delete other people’s data.
- Stop and report as soon as you can show the problem; do not go further than you need to.
- No denial-of-service testing, no automated scanning that degrades the service, no social engineering of our staff or customers, and no physical attacks.
What we promise
- A reply from a person within 3 working days, with a reference for your report.
- An update when we have confirmed it, and again when it is fixed.
- We will not take legal action against, or suspend the account of, anyone who reports in good faith and follows the points above.
- Credit for the finding if you want it. We do not currently pay bounties.
In scope
The Disclosure website and app, their sign-in and account features, and our public API. Out of scope: other companies’ services we link to, findings that need a compromised device or browser, missing best-practice headers with no demonstrated effect, and reports from automated tools without a working example.