CaseLeadCaseLead
Security

Vulnerability disclosure policy

Last updated: August 4, 2026. If you've found a security problem in our website or platform, we want to hear from you — and we'll treat you like the ally you are.

How to report

Use the contact form with "SECURITY" at the start of your message. Include: what you found, where (URL/endpoint), steps to reproduce, and how to reach you. We acknowledge reports within 3 business days and aim to give you a resolution status within 30 days. A machine-readable pointer to this policy lives at /.well-known/security.txt.

Scope

Ground rules — our commitment to you

What happens on our side

Reports go to the engineering owner directly (we're a small team — no ticket purgatory). Confirmed issues get fixed with the same discipline as the platform itself: root cause, fix, verification, and an audit trail. Significant findings are credited on request.

Security architecture & validation · caselead.ai