How to report
Report a security issue
Email edward@alpha-scaling.com.
To help us investigate quickly, please include as much of the following as you can:
- a clear description of the issue and its potential impact;
- the steps to reproduce it, or a short proof of concept;
- the affected URL, endpoint, or area of the product;
- any relevant requests, logs, or screenshots.
Good-faith research
If you make a good-faith effort to follow this policy while investigating and reporting an issue, we will treat your research as authorized under this policy. We will not pursue legal action against you for accidental, good-faith violations, and we will work with you to understand and resolve the issue.
What we ask
To protect our clients' data while you research, we ask that you:
- give us a reasonable opportunity to investigate and remediate an issue before disclosing it publicly;
- access or modify only data that belongs to you or to test accounts you control — never another user's or organization's data;
- access only the minimum necessary to demonstrate a vulnerability, and do not download, retain, or share data you encounter;
- avoid anything that could disrupt or degrade our services, such as denial-of-service testing, spam, or high-volume automated scanning;
- do not use social engineering, phishing, or physical attacks against our staff, users, or facilities.
What to expect
When you report an issue, we will acknowledge your report, investigate, and keep you reasonably informed of our progress. We aim to remediate valid issues in a timeframe appropriate to their severity, and we are glad to credit researchers who report valid issues if you would like recognition.
Bug bounty
Alpha Scaling does not operate a paid bug bounty program at this time, and we cannot guarantee monetary rewards. We are grateful for responsible reports and will gladly acknowledge your contribution.