Security
Keeping customer conversations and data safe is foundational to ConnectBetter. If you believe you've found a vulnerability, we want to hear from you, and we'll work with you to get it fixed.
Report a vulnerability
Email us directly. Please report privately and give us a reasonable chance to fix the issue before any public disclosure.
security@connectbetter.coWhat to include
A good report helps us reproduce and triage quickly. Where possible, please include:
- A clear description of the issue and its potential impact.
- Step-by-step instructions to reproduce it (proof-of-concept welcome).
- The affected URL, endpoint, or component, and any relevant request/response.
- Your assessment of severity, if you have one.
What you can expect
- We aim to acknowledge new reports within three business days.
- We triage and prioritize by severity (using CVSS), assign an owner, and track each finding to closure.
- We'll keep you updated on remediation progress and let you know when a fix ships.
- Critical fixes are deployed out-of-band through our standard pipeline and verified before release.
Testing guidelines & safe harbor
We consider security research conducted in good faith under these guidelines to be authorized, and we will not pursue legal action for it. When testing, please:
- Only access accounts and data that belong to you, or that you have explicit permission to test.
- Avoid privacy violations, data destruction, and any degradation of our service (no denial-of-service or spam).
- Stop and report immediately if you encounter customer data, and don't store, share, or exfiltrate it.
- Give us reasonable time to remediate before disclosing publicly.