Skip to content
SysGlass

Security

Security Policy

SysGlass accepts responsible vulnerability reports for our public services and apps. This policy does not authorize active testing, scanning, exploitation, or abuse of systems without prior written permission from SysGlass.

Reporting

If you accidentally discover a vulnerability during normal use, stop testing immediately and report it to security@sysglass.com within 24 working hours of discovery. Include the affected service, a concise description, and enough non-destructive evidence for us to reproduce the issue.

No Unauthorized Testing

Do not perform vulnerability scanning, exploitation, denial-of-service testing, social engineering, persistence, data access, data extraction, or testing against systems you do not own or administer unless SysGlass has granted explicit written permission before the activity starts.

No Paid Bug Bounty

SysGlass does not operate a paid bug bounty program. We do not pay rewards, bounties, invoices, or finder fees unless a written agreement has been made with SysGlass before any testing or research begins.

Disclosure

Do not publicly disclose vulnerability details, exploit steps, screenshots, or proof-of-concept material before receiving written permission from SysGlass. Reports that involve real customer data, service disruption, or unauthorized access must stop immediately and be reported without further probing.

Policy File

Automated tools should use /.well-known/security.txt. General product terms are available in the Terms of Service.