Security

Keeping customer conversations and data safe is foundational to ConnectBetter. If you believe you've found a vulnerability, we want to hear from you, and we'll work with you to get it fixed.

Report a vulnerability

Email us directly. Please report privately and give us a reasonable chance to fix the issue before any public disclosure.

security@connectbetter.co

What to include

A good report helps us reproduce and triage quickly. Where possible, please include:

  • A clear description of the issue and its potential impact.
  • Step-by-step instructions to reproduce it (proof-of-concept welcome).
  • The affected URL, endpoint, or component, and any relevant request/response.
  • Your assessment of severity, if you have one.

What you can expect

  • We aim to acknowledge new reports within three business days.
  • We triage and prioritize by severity (using CVSS), assign an owner, and track each finding to closure.
  • We'll keep you updated on remediation progress and let you know when a fix ships.
  • Critical fixes are deployed out-of-band through our standard pipeline and verified before release.

Testing guidelines & safe harbor

We consider security research conducted in good faith under these guidelines to be authorized, and we will not pursue legal action for it. When testing, please:

  • Only access accounts and data that belong to you, or that you have explicit permission to test.
  • Avoid privacy violations, data destruction, and any degradation of our service (no denial-of-service or spam).
  • Stop and report immediately if you encounter customer data, and don't store, share, or exfiltrate it.
  • Give us reasonable time to remediate before disclosing publicly.