Security

Responsible disclosure

We take security seriously. If you discover a vulnerability, please report it responsibly so we can protect our customers.

Scope

Reports are in scope for leadforgrow.com, app.leadforgrow.com, and our public API endpoints. Social engineering, physical attacks, and denial-of-service tests are out of scope.

How to report

1

Report privately

Email security@leadforgrow.com with a detailed description, steps to reproduce, and impact assessment.

2

We acknowledge

Our security team responds within 48 hours with a ticket reference and initial triage.

3

We investigate

We validate the report, assess severity (CVSS), and work on a fix with regular status updates.

4

We resolve & credit

Once patched, we notify you and — with your permission — acknowledge your contribution.

Response SLA

Initial response within 48 hours. Critical issues prioritized immediately.

Safe harbor

  • Act in good faith and avoid privacy violations or data destruction
  • Give us reasonable time to investigate and remediate before public disclosure
  • Do not access or modify data belonging to other customers
  • We will not pursue legal action against researchers who follow this policy

For general security information, visit our Security page.