Security researchers are allies. This policy tells you exactly what you can test, how to report securely, what timelines to expect, and the safe-harbor protections that apply to good-faith research. We built our platform to detect threats — we want researchers to help us keep it secure.
Our commitment to security researchers
ManySignal believes that responsible security research makes our platform and our customers safer. We welcome reports from independent security researchers, customers, and members of the broader security community who identify potential vulnerabilities in our systems.
This Vulnerability Disclosure Policy ("VDP") describes the scope of our program, the rules of engagement, how to report securely, the response timelines you can expect, and our approach to coordinated disclosure. We follow a safe-harbor model: if you comply with this policy, we will not initiate or support legal action against you for good-faith security research.
Safe harbor
ManySignal will not pursue civil or criminal action against researchers who: (a) discover and report vulnerabilities in good faith in accordance with this policy; (b) avoid accessing, modifying, or deleting data beyond what is necessary to demonstrate the vulnerability; (c) do not exploit a vulnerability beyond the minimum required to confirm its existence; (d) do not conduct denial-of-service attacks or disrupt services for other users; (e) do not perform social engineering or phishing attacks against ManySignal employees or customers; and (f) report the vulnerability to us before public disclosure and give us adequate time to investigate and remediate.
This safe harbor applies specifically to activities within the scope defined in this policy. Activities outside scope are not covered by the safe harbor. ManySignal's legal and security teams may, in their discretion, extend safe harbor to out-of-scope reports submitted in genuine good faith.
Scope — in scope targets
The following assets are in scope for this program:
- The ManySignal web application at app.manysignal.com and all sub-domains under *.manysignal.com used for the production platform
- The ManySignal public API (api.manysignal.com), including all documented API endpoints
- The ManySignal marketing website at manysignal.com
- ManySignal-published mobile applications (iOS and Android), if any
- Publicly accessible ManySignal-owned cloud storage buckets or object stores
- ManySignal-published open-source libraries hosted on the ManySignal GitHub organisation (github.com/manysignal)
Scope — out of scope targets
The following are explicitly out of scope. Testing against these targets is not covered by the safe harbor:
- Any system, network, or infrastructure not listed above, including customer-owned environments connected to ManySignal via integrations
- Third-party services and sub-processors (AWS, GCP, Datadog, Sentry, etc.) — report these to the relevant vendor
- Social engineering, phishing, or physical security attacks against ManySignal personnel or facilities
- Denial-of-service (DoS/DDoS) attacks
- Automated scanning that generates excessive load on production systems
- Attacks that require physical access to ManySignal hardware
- Vulnerabilities in software that ManySignal does not maintain (e.g., OS packages, open-source dependencies not specifically written by ManySignal)
- Known public vulnerabilities in third-party software without demonstrated exploitability in a ManySignal context
Reporting a vulnerability
Submit vulnerability reports to security@manysignal.com. For sensitive reports, encrypt your email using our PGP key (fingerprint: 4F2A 8C3B 1D7E 9A56 F012 3489 BB4C 92E7 D8F1 00AC). The full public key is available at manysignal.com/security.asc and on the MIT PGP key server.
Your report should include: (a) a description of the vulnerability and its potential impact; (b) the specific URL or API endpoint affected; (c) step-by-step instructions to reproduce the issue; (d) proof-of-concept code, screenshots, or screen recordings, if available; (e) your assessment of the CVSS score, if known; (f) your preferred contact information for follow-up; and (g) whether you prefer public credit upon disclosure.
Do not submit vulnerability reports through the standard customer support portal, as those channels are not monitored for security-sensitive disclosures.
Response SLAs
| Milestone | Target timeline |
|---|---|
| Initial acknowledgement | Within 1 business day of receipt |
| Triage and severity assessment | Within 5 business days |
| Remediation plan shared | Within 14 calendar days for Critical/High; 30 days for Medium |
| Patch deployed to production | Critical: within 7 days; High: within 30 days; Medium: within 90 days |
| Public disclosure (coordinated) | 90 days after initial report, or earlier by mutual agreement |
If we determine that a reported issue does not qualify as a security vulnerability, we will explain our reasoning. We encourage researchers to discuss that assessment with us before moving to public disclosure.
Coordinated disclosure timeline
ManySignal follows a 90-day coordinated disclosure policy. We ask researchers to give us 90 days from initial report to patch and notify affected parties before publishing details publicly. We will work to patch critical vulnerabilities well within this window.
If we require additional time beyond 90 days due to patch complexity, we will communicate this to the reporter and agree on an extension. We will not ask for extensions beyond 120 days from the initial report for Critical or High severity vulnerabilities. For vulnerabilities being actively exploited in the wild, we will coordinate with the reporter on expedited disclosure.
We will credit researchers by name (or handle, at their preference) in the CVE advisory and in our security advisories page, unless the researcher requests anonymity.
What we do not offer
ManySignal does not currently operate a paid bug bounty program. We offer recognition, coordinated disclosure support, and our sincere thanks. We are evaluating a formal bug-bounty program for 2027 and will announce it here when available.
We do not make commitments to researchers to preserve their account access or provide special product access in exchange for vulnerability reports. Any testing must be conducted against accounts and environments you own, or against the designated test tenant we may provide upon request for valid researchers.
Questions and contact
For questions about this policy, acceptable testing boundaries, or to request a test tenant, contact security@manysignal.com. For general security questions that do not involve a vulnerability disclosure, visit our Security page.
If you believe a vulnerability you have reported is being handled in bad faith or is being actively exploited before we have patched it, you may contact our Chief Security Officer directly at cso@manysignal.com. We take our obligations to the security research community seriously.
Questions about this document?
Contact our legal team at security@manysignal.com. For security disclosure, use security@manysignal.com.