Coordinated vulnerability reporting

Responsible Disclosure Policy

We welcome good-faith reports that help protect OrgRecon and its users. Please investigate carefully, minimize impact, and give us a reasonable opportunity to resolve the issue before public disclosure.

Effective July 27, 2026

Report OrgRecon vulnerabilities privately to [email protected]. Do not include credentials, Salesforce record contents, customer reports, access tokens, or unnecessary personal data.

1. Scope

This policy applies to security vulnerabilities in systems and software operated by OrgRecon, including:

Salesforce, WorkOS, Resend, Cloudflare, and other provider-operated products remain subject to their own disclosure programs.

2. Out of scope

The following are not authorized by this policy:

3. Research rules

When investigating a potential issue:

4. What to include

A useful report includes:

Send the report to [email protected] with a subject such as “Security report: brief issue summary.” Do not send active credentials, session cookies, private keys, raw Salesforce responses, or customer record contents.

5. What to expect from us

We aim to acknowledge a valid report within three business days and provide an initial triage response within seven business days. Resolution time depends on severity, complexity, and provider dependencies. We will share material status updates when possible and coordinate disclosure timing with you.

OrgRecon does not currently operate a paid bug-bounty program. We may acknowledge researchers who provide useful reports if they request recognition and doing so does not create additional risk.

6. Safe harbor

If you act in good faith, follow this policy, avoid privacy violations and service disruption, and report the issue promptly, OrgRecon will consider your research authorized under this policy and will not pursue legal action against you for that research. If a third party initiates legal action related to compliant research, we will make reasonable efforts to clarify that your activity followed this policy.

This safe harbor does not authorize activity against third-party systems, excuse violations of law, or bind a third party. If you are uncertain whether a test is permitted, contact us before proceeding.

7. Customer or Salesforce findings

If you discover an exposure in a Salesforce organization or Experience Cloud site, report it to the organization’s authorized security contact. A customer configuration issue is not automatically an OrgRecon vulnerability. Issues in Salesforce-owned products should be reported through Salesforce’s vulnerability disclosure process.

8. Contact

Security reports and questions about this policy: [email protected].