If you've found a security issue in Sigbot, we want to hear about it. Here's how to report it, and what to expect from us.
Sigbot values the work of independent security researchers in helping keep our customers' data safe. This policy describes what systems and research techniques are covered, how to submit a report, and what you can expect from us in response.
If you make a good-faith effort to comply with this policy during your security research, we will consider that research authorised, we will not pursue legal action against you for it, and we will work with you to understand and resolve the issue quickly.
This policy applies to:
Email security@sigbot.co with:
Please do not include actual Customer Data in your report — use test accounts or synthetic data wherever possible. For sensitive reports, you can also use the in-app feedback and report form.
| Milestone | Target |
|---|---|
| Acknowledgement of your report | Within 24–48 hours |
| Initial triage / validation | Within 5–10 business days |
| Status updates while we work on a fix | Weekly |
We ask that you give us a reasonable opportunity to investigate and remediate an issue before disclosing it publicly, and that you coordinate the timing and content of any public disclosure with us in advance.
We do not currently run a paid bounty program. We're grateful for every report regardless, and will credit researchers who ask to be credited once an issue is resolved.