Disclosure

Security

Report a security vulnerability

If you believe you have found a security problem in Disclosure, tell us here. We read every report and reply to each one.

What we ask

  • Give us the detail privately first, and reasonable time to fix it before you publish anything.
  • Test only against your own account. Do not read, change or delete other people’s data.
  • Stop and report as soon as you can show the problem; do not go further than you need to.
  • No denial-of-service testing, no automated scanning that degrades the service, no social engineering of our staff or customers, and no physical attacks.

What we promise

  • A reply from a person within 3 working days, with a reference for your report.
  • An update when we have confirmed it, and again when it is fixed.
  • We will not take legal action against, or suspend the account of, anyone who reports in good faith and follows the points above.
  • Credit for the finding if you want it. We do not currently pay bounties.

In scope

The Disclosure website and app, their sign-in and account features, and our public API. Out of scope: other companies’ services we link to, findings that need a compromised device or browser, missing best-practice headers with no demonstrated effect, and reports from automated tools without a working example.

Send a report

Prefer email? Write to team@disclosure.co with “Security report” in the subject. For how we protect accounts, see Security and access; for service problems, see System status.