How to report
Use the contact form with "SECURITY" at the start of your message. Include: what you found, where (URL/endpoint), steps to reproduce, and how to reach you. We acknowledge reports within 3 business days and aim to give you a resolution status within 30 days. A machine-readable pointer to this policy lives at /.well-known/security.txt.
Scope
- In scope: caselead.ai (this website) and the public demo at app.caselead.ai.
- Out of scope: agency production deployments (report those directly to the agency and to us), denial-of-service and volumetric testing, social engineering, physical attacks, and third-party services we don't operate.
Ground rules — our commitment to you
- We will not pursue or support legal action against good-faith security research that respects this policy — test only against the public site and demo, don't access or modify data that isn't yours, and don't degrade the service for others.
- The public demo contains only de-identified sample data. If you somehow encounter anything that appears to be real personal or case information, stop, don't retain it, and report immediately.
- Give us reasonable time to fix before public disclosure; we're glad to coordinate timelines and credit you (or keep you anonymous — your call).
What happens on our side
Reports go to the engineering owner directly (we're a small team — no ticket purgatory). Confirmed issues get fixed with the same discipline as the platform itself: root cause, fix, verification, and an audit trail. Significant findings are credited on request.