Security Disclosure Policy
Last updated: June 27, 2026
Cardstead values responsible reports of security vulnerabilities. This policy explains how to report a vulnerability and what conduct is authorized.
How to report
Send security reports to support@cardstead.com. Include the affected URL or endpoint, a clear description, reproduction steps, impact, relevant request IDs, screenshots or proof-of-concept details, and any tenant or test account used.
Do not include personal information, tenant data, secrets, payment information, or other sensitive data unless it is strictly necessary to demonstrate the issue.
Authorized research
- Use only accounts, tenants, data, and systems you own or are authorized to test.
- Stop testing and report immediately if you access another tenant's data, customer data, credentials, secrets, logs, backups, infrastructure, or non-public systems.
- Avoid privacy violations, service degradation, data destruction, persistence, lateral movement, social engineering, phishing, spam, physical attacks, and denial-of-service testing.
- Give Cardstead a reasonable opportunity to investigate and remediate before publicly disclosing the issue.
Out of scope
- Denial-of-service, spam, social engineering, physical attacks, and attacks against third-party providers.
- Reports based only on missing security headers or scanner output without a practical exploit or meaningful risk.
- Clickjacking or mixed-content findings on pages that do not expose sensitive actions or data.
- Issues requiring a compromised user account, compromised device, outdated browser, malware, or privileged local network access without a service-side vulnerability.
- Rate-limit findings without demonstrated security impact beyond normal abuse-prevention tuning.
Safe harbor
If you follow this policy, act in good faith, avoid harm, and report promptly, Cardstead will not pursue legal action against you for the authorized research described here. This safe harbor does not apply to extortion, data theft, privacy violations, destructive testing, service disruption, social engineering, or actions outside this policy.
No bounty program
Cardstead does not currently operate a public bug bounty program and does not promise payment or rewards for reports. We appreciate responsible reports and will credit researchers when appropriate and mutually agreed.
Our process
We aim to acknowledge credible reports, investigate impact, prioritize remediation based on risk, and communicate when the issue is resolved or when more information is needed. Response times may vary based on severity, report quality, and operational load.