Vulnerability disclosure policy
If you have found a security problem, we would rather hear it from you than from a customer. This is where to send it and what we will do.
Last updated . Material changes are announced to workspace owners by email before they take effect.
1How to report
Email support@isixty.co.za. Include enough to reproduce it — a URL, a request, the steps. If it is sensitive, say so and we will arrange an encrypted channel before you send details.
You do not need to have a proof of concept, and you do not need to be certain. A well-described suspicion is worth more than silence.
2What we promise
- To acknowledge your report within two business days.
- To tell you what we think within ten business days — including if we think it is not a vulnerability, and why.
- To keep you informed while we fix it, and to tell you when it is done.
- Not to pursue legal action against you, or to ask anyone else to, for research conducted in good faith under this policy.
- To credit you publicly if you want it, and not to if you do not.
We do not run a paid bounty. We will say so up front rather than let you find out after the work.
3What we ask
- Give us reasonable time to fix it before telling anyone else. We will not use that as a way to delay indefinitely — if we go quiet, say so, and set a date.
- Do not access, modify or delete data that is not yours. If you land in someone else’s document, stop and tell us what you saw so we can assess it.
- Do not run denial-of-service tests, send bulk email through the platform, or test physical or social engineering.
- Use your own workspace and your own test documents.
The signing links carry other people’s confidential agreements. That is the part of this system where careless testing does real harm to somebody who never agreed to be part of it.
4In scope
The application, its API, the transparency log endpoints, and the signing flow. Anything that lets one workspace reach another’s data, anything that forges or replays a signing link, and anything that lets a sealed document be altered without detection is particularly wanted.
5Out of scope
- Findings from automated scanners without a demonstrated impact.
- Missing hardening headers with no exploit path.
- Rate limiting on endpoints that do not change data or send mail.
- Social engineering of our staff or our customers.
- Vulnerabilities in a sub-processor’s own systems — report those to them; tell us too, and we will follow up.
- The published transparency log being public. It is designed to be.