Responsible Disclosure Policy
We welcome good-faith reports that help protect OrgRecon and its users. Please investigate carefully, minimize impact, and give us a reasonable opportunity to resolve the issue before public disclosure.
1. Scope
This policy applies to security vulnerabilities in systems and software operated by OrgRecon, including:
- orgrecon.com and its first-party public services;
- app.orgrecon.com, the authenticated OrgRecon application, and its first-party APIs;
- OrgRecon scanner, report, authentication, authorization, and data-handling controls; and
- OrgRecon-owned packages or repositories that explicitly reference this policy.
Salesforce, WorkOS, Resend, Cloudflare, and other provider-operated products remain subject to their own disclosure programs.
2. Out of scope
The following are not authorized by this policy:
- testing a Salesforce customer organization, Experience Cloud site, or other third-party asset that you do not own or have permission to assess;
- accessing another OrgRecon user’s reports, scans, account, or authorized hosts beyond the minimum needed to demonstrate a suspected boundary failure;
- social engineering, phishing, physical attacks, spam, denial-of-service testing, high-volume automation, or resource exhaustion;
- malware deployment, persistence, credential attacks, password spraying, or attempts to obtain secrets;
- reports based only on automated scanner output without a reproducible security impact; and
- third-party platform vulnerabilities that do not arise from OrgRecon’s implementation or configuration.
3. Research rules
When investigating a potential issue:
- use your own OrgRecon account, your own test data, and assets you are authorized to assess;
- make the smallest number of requests needed to verify the issue;
- stop immediately if you encounter customer data, credentials, tokens, private reports, or service instability;
- do not download, retain, modify, delete, or publicly disclose data that is not yours;
- do not establish persistence or pivot to another system, user, tenant, or provider; and
- allow us reasonable time to investigate and remediate before publishing details.
4. What to include
A useful report includes:
- a concise description of the vulnerability and its security impact;
- the affected OrgRecon URL, component, API, or version;
- clear, reproducible steps using sanitized test data;
- the date and time of testing and any relevant request identifiers;
- screenshots or minimal proof with secrets and personal data removed; and
- your preferred contact information and any planned disclosure date.
Send the report to [email protected] with a subject such as “Security report: brief issue summary.” Do not send active credentials, session cookies, private keys, raw Salesforce responses, or customer record contents.
5. What to expect from us
We aim to acknowledge a valid report within three business days and provide an initial triage response within seven business days. Resolution time depends on severity, complexity, and provider dependencies. We will share material status updates when possible and coordinate disclosure timing with you.
OrgRecon does not currently operate a paid bug-bounty program. We may acknowledge researchers who provide useful reports if they request recognition and doing so does not create additional risk.
6. Safe harbor
If you act in good faith, follow this policy, avoid privacy violations and service disruption, and report the issue promptly, OrgRecon will consider your research authorized under this policy and will not pursue legal action against you for that research. If a third party initiates legal action related to compliant research, we will make reasonable efforts to clarify that your activity followed this policy.
This safe harbor does not authorize activity against third-party systems, excuse violations of law, or bind a third party. If you are uncertain whether a test is permitted, contact us before proceeding.
7. Customer or Salesforce findings
If you discover an exposure in a Salesforce organization or Experience Cloud site, report it to the organization’s authorized security contact. A customer configuration issue is not automatically an OrgRecon vulnerability. Issues in Salesforce-owned products should be reported through Salesforce’s vulnerability disclosure process.
8. Contact
Security reports and questions about this policy: [email protected].