Trust

Vulnerability
disclosure.

Found a security issue in PropSocket? Tell us. This page covers how to report it, what's in scope, and the protections we extend to researchers acting in good faith.

Last reviewed: 2026-07-11

We take the security of PropSocket and the data our customers trust us with seriously. If you've found a vulnerability, we want to hear about it, and we'll work with you to confirm and fix it. This policy explains how to report responsibly and what you can expect from us in return.

How to report

Emailsecurity@propsocket.iowith:

  • A clear description of the issue and the potential impact.
  • Steps to reproduce it — proof-of-concept code or a short screen recording helps.
  • The affected URL, endpoint, or component.
  • Any accounts or test data you used (so we can clean up afterward).

Please report directly to us first and give us a reasonable window to respond before any public disclosure. We don't operate a paid bug-bounty program at this time, so there is no monetary reward — but we'll credit researchers who want recognition (see below).

Scope

In scope

  • The PropSocket REST API and the systems behind it.
  • The tenant dashboard.
  • This marketing website and its subdomains that we operate.
  • Webhook delivery, signing, and authentication mechanisms.

Out of scope

  • Findings that require physical access to a user's device.
  • Social engineering of our staff, customers, or vendors.
  • Denial-of-service or volumetric attacks, and any test that degrades service for others.
  • Reports from automated scanners with no demonstrated, exploitable impact.
  • Issues in third-party services we use (report those to the vendor; tell us too if customer data is at risk).
  • Our Trust Center (hosted by Vanta) and our status page (hosted by Atlassian). We manage the content and configuration; the underlying platforms belong to those vendors, so report platform vulnerabilities to Vanta or Atlassian. If you find a misconfiguration in something we control there, tell us too.
  • Best-practice suggestions with no security impact (e.g., missing headers without a working exploit).

Safe harbor

If you make a good-faith effort to follow this policy, we will treat your research as authorized, will not pursue or support legal action against you for it, and will work with you to resolve the issue quickly. Good faith means:

  • Only interacting with accounts you own or have explicit permission to test.
  • Not accessing, modifying, or deleting other customers' data — if you encounter it, stop and report it.
  • Not exfiltrating data beyond the minimum needed to prove the issue.
  • Giving us a reasonable time to remediate before disclosing publicly.

If legal action is initiated by a third party against you for activity that complied with this policy, we'll make it known that your actions were authorized.

What to expect from us

  • Acknowledgment within3 business days of your report.
  • An initial assessment — whether we can reproduce it and our view of severity — as soon as we've investigated.
  • Honest status updates while we work on a fix, and a heads-up when it ships.
  • Credit, if you want it. We're glad to publicly thank researchers who report responsibly. Tell us how you'd like to be named, or stay anonymous — your call.

Found something? Send it our way.

Report responsibly to security@propsocket.io. We acknowledge within three business days and work the fix with you.