Security
Responsible disclosure
We take security seriously. If you discover a vulnerability, please report it responsibly so we can protect our customers.
Scope
Reports are in scope for leadforgrow.com, app.leadforgrow.com, and our public API endpoints. Social engineering, physical attacks, and denial-of-service tests are out of scope.
How to report
Report privately
Email security@leadforgrow.com with a detailed description, steps to reproduce, and impact assessment.
We acknowledge
Our security team responds within 48 hours with a ticket reference and initial triage.
We investigate
We validate the report, assess severity (CVSS), and work on a fix with regular status updates.
We resolve & credit
Once patched, we notify you and — with your permission — acknowledge your contribution.
Contact
security@leadforgrow.comResponse SLA
Initial response within 48 hours. Critical issues prioritized immediately.
Safe harbor
- Act in good faith and avoid privacy violations or data destruction
- Give us reasonable time to investigate and remediate before public disclosure
- Do not access or modify data belonging to other customers
- We will not pursue legal action against researchers who follow this policy
For general security information, visit our Security page.