Vulnerability Disclosure Policy
SyncReach takes the security of our systems seriously. If you believe you've found a security vulnerability, here's how to report it.
If you believe you've found a security vulnerability affecting SyncReach, we want to know about it. This page explains how to report it, what's in scope, and the ground rules that keep good-faith research protected.
01 No bug bounty program
We do not currently offer a paid bug bounty program, and we do not commit to compensation of any kind for reports submitted through this process. We may, at our sole discretion, acknowledge valid reports.
02 How to report
Email [email protected] with:
- A description of the vulnerability and its potential impact
- Step-by-step reproduction instructions or a proof of concept
- Any relevant logs, screenshots, or scripts
We aim to acknowledge reports within 5 business days.
03 Scope
In scope: syncreach.io and its subdomains, and our public GitHub repositories under github.com/SyncReach.
Out of scope: third-party services we integrate with (e.g. Cloudflare, GitHub Pages, our email provider) — please report those directly to the respective vendor.
04 Ground rules & safe harbor
We will not pursue legal action against researchers who, in good faith:
- Report a vulnerability promptly and do not disclose it publicly before we've had a reasonable opportunity to address it
- Avoid privacy violations, data destruction, and service disruption during testing
- Do not access, modify, or exfiltrate data beyond what's needed to demonstrate the issue
- Do not use automated scanning tools that generate excessive traffic
- Interact only with test/demo accounts or their own account, never another user's data
- Comply with applicable Canadian law, including the Criminal Code provisions on unauthorized computer access — this policy authorizes good-faith testing within the scope and rules above, but does not authorize illegal activity
If your research stays within these guidelines, we consider it authorized and won't pursue civil or criminal legal action, or refer the matter to law enforcement, on account of it.
05 What happens after you report
- We confirm receipt.
- We investigate and validate the finding.
- We work on a fix, with priority based on severity.
- We may follow up with you for clarification.
- We don't currently publish a public researcher hall of fame, but we're happy to credit you privately if you'd like.