We welcome reports from security researchers and take them seriously. If you believe you have found a vulnerability in Tickbox, please let us know.
How to report
Email security@usetickbox.com with enough detail for us to reproduce the issue: what you found, where, the steps to reproduce, and its potential impact. A proof of concept is helpful. Please report promptly after discovery.
Please do
- Give us a reasonable time to investigate and fix before any public disclosure.
- Only test against your own account and data.
- Act in good faith and avoid privacy violations, data destruction, or service disruption.
Please don't
- Access, modify, or delete data that isn't yours.
- Run denial-of-service, spam, or automated high-volume testing.
- Use social engineering, phishing, or physical attacks against our people or infrastructure.
Our commitment (safe harbour)
If you follow this policy in good faith, we will not pursue or support legal action against you for your research, and we will work with you to understand and resolve the issue quickly. We will acknowledge your report and keep you updated on our progress.
Scope
This policy covers the Tickbox application at usetickbox.com. Issues in third-party services we use (such as Cloudflare, Stripe, Anthropic, or Resend) should be reported to those providers directly, though we're happy to help route them.
Machine-readable contact details are published at /.well-known/security.txt.
Answer your questionnaire in minutes
Drop it in and Tickbox drafts every answer for you to review. Your first few are free.
Try it free