Skip to main content
SIXSENTENCES_

RESPONSIBLE DISCLOSURE

Report a security issue

We welcome good-faith reports that help protect researchers and their work. Send the details to hello@sixsentences.com with the subject "Security report". Do not include passwords, access tokens, private research content or participant data in the first message.

What to include

  • the affected URL or feature and the observed impact,
  • minimal, reproducible steps using your own test account,
  • the time of the test and a safe way to contact you, and
  • screenshots with personal data and credentials removed.

Safe research

Please avoid accessing another person's workspace or data, disrupting availability, running automated volume tests, sending unsolicited messages, uploading malware, or changing and deleting data. Stop when you have enough evidence to explain the issue. We do not authorize testing of our infrastructure providers or other third parties.

What happens next

We aim to acknowledge a report within two business days, keep you informed during validation and coordinate disclosure once affected users are protected. Timelines depend on severity and complexity. We will not pursue legal action against good-faith research that follows this policy and applicable law.

Urgent privacy incidents

If you believe personal data is actively exposed, state "urgent privacy incident" in the subject. Do not download additional records to prove scope.