·Responsible disclosure

Found a vulnerability? Tell us.

We welcome reports from security researchers and customers. Submit the form and it goes straight to our team, we'll investigate, keep you updated, and fix it. We won't pursue action against anyone acting in good faith to help us keep the platform safe.

Prefer email? Write to [email protected].

Machine-readable details: /.well-known/security.txt

Goes straight to our team · We reply within 3 business days

01What to include
  • A clear description of the issue and why you believe it's a security problem.
  • Step-by-step instructions to reproduce it.
  • The affected URL, page, or API endpoint.
  • Any proof-of-concept, request/response, or screenshots that help.
  • How we can reach you for follow-up (and whether you'd like credit).
02What to expect from us
  • We aim to acknowledge your report within 3 business days.
  • We'll let you know whether we can reproduce it and keep you updated as we work on a fix.
  • We'll tell you when the issue is resolved, and credit you if you'd like.
03Scope
In scope
  • change-tca.com and its subdomains (client, agent, admin, and branded tenant domains).
  • The platform API.
  • Authentication, authorization, and tenant-isolation flaws.
Out of scope
  • Denial-of-service or volumetric/load testing.
  • Social engineering, phishing, or physical attacks against staff or offices.
  • Reports from automated scanners without a demonstrated, exploitable impact.
  • Issues in third-party services we use, which should be reported to those vendors.
  • Best-practice suggestions with no concrete security impact (e.g. missing headers alone).
04Testing guidelines
  • Use only your own test accounts and data while investigating.
  • Give us a reasonable chance to fix an issue before disclosing it publicly.
  • Don't access, modify, or delete data that isn't yours.
  • Don't degrade or disrupt the service for other users.

Recognition

We don't run a paid bug-bounty program at this time, but we're genuinely grateful for responsible reports and will gladly credit you for a valid finding if you'd like to be named.