SIGBOT
Legal & Trust

Vulnerability Disclosure Policy

Last updated: 19 July 2026

If you've found a security issue in Sigbot, we want to hear about it. Here's how to report it, and what to expect from us.

Sigbot values the work of independent security researchers in helping keep our customers' data safe. This policy describes what systems and research techniques are covered, how to submit a report, and what you can expect from us in response.

Safe Harbor

If you make a good-faith effort to comply with this policy during your security research, we will consider that research authorised, we will not pursue legal action against you for it, and we will work with you to understand and resolve the issue quickly.

1. Scope

This policy applies to:

Out of scope

2. How to Report

Email security@sigbot.co with:

Please do not include actual Customer Data in your report — use test accounts or synthetic data wherever possible. For sensitive reports, you can also use the in-app feedback and report form.

3. What to Expect

MilestoneTarget
Acknowledgement of your reportWithin 24–48 hours
Initial triage / validationWithin 5–10 business days
Status updates while we work on a fixWeekly

We ask that you give us a reasonable opportunity to investigate and remediate an issue before disclosing it publicly, and that you coordinate the timing and content of any public disclosure with us in advance.

4. Recognition

We do not currently run a paid bounty program. We're grateful for every report regardless, and will credit researchers who ask to be credited once an issue is resolved.

5. Contact

security@sigbot.co