Vulnerability Disclosure Policy
We take the security of teameverflow.com and our customers seriously. If you find a vulnerability, please tell us privately so we can fix it.
Last updated: July 2026
How to report
Email info@teameverflow.com with the subject line "Security vulnerability report". Include a clear description of the issue, the URL or system affected, and steps to reproduce it. Add screenshots or a short proof of concept when helpful. Do not include customer personal data in your report.
If that mailbox is unavailable, use our contact form and mark the message as a security report.
What we ask
- Give us a reasonable chance to fix the issue before public disclosure.
- Do not access, change, or delete data that is not yours.
- Do not disrupt service (no DoS, spam, or social engineering of staff or customers).
- Do not use automated scans that create heavy load without permission.
What we will do
- Confirm we received your report as soon as we can.
- Investigate and keep you updated when we have meaningful progress.
- Fix confirmed issues and credit you if you want public acknowledgment.
Safe harbor
If you follow this policy in good faith, we will not pursue legal action related to your research on our public website. This does not authorize testing of third-party systems, payment processors, or customer accounts you do not own.
Related: Privacy Policy · Terms of Service