Stacker

Search Documentation

Search for pages and topics in the documentation

Vulnerability Disclosure Policy

We take the security of Stacker and of the data our customers entrust to us seriously, and we value the work of security researchers. If you believe you have found a vulnerability in one of our systems, we want to hear from you. We will work with you to understand and resolve the issue quickly, and we will not take legal action against researchers who act in good faith under this policy.

Stacker Software Ltd · Version 1.0 · 17 September 2026 · Machine-readable contact details are published at /.well-known/security.txt.

Scope

In scope

  • stacker.ai and *.stacker.ai (including staging.stacker.ai)
  • deedspring.com and *.deedspring.com
  • *.outportal.ai (customer portals) and the Stacker APIs under /api/
  • The Stacker mobile apps and browser-facing components we publish
  • Our Google, Microsoft, Slack and other third-party integrations as implemented by Stacker (for example our OAuth flows and token handling)

Out of scope

  • Customer-built portals' content and third-party sites we link to
  • Denial-of-service, volumetric or resource-exhaustion testing
  • Social engineering, phishing or physical attacks against Stacker staff or customers
  • Vulnerabilities in third-party services we use (Google, Cloudflare, PostHog, Stripe, Resend, Slack) — please report those to the vendor
  • Reports from automated scanners with no demonstrated impact, missing best-practice headers without an exploit, or clickjacking on pages with no sensitive actions
  • Anything requiring access to another customer's real account or data — use accounts you create yourself

Rules of engagement

  • Only test against accounts and workspaces you own or have explicit permission to use. Create a free workspace for testing.
  • Do not access, modify or delete data that is not yours. If you encounter another customer's data, stop, do not retain it, and tell us.
  • Do not run denial-of-service tests, spam our systems, or degrade service for others.
  • Do not publicly disclose the issue before we have resolved it (see Coordinated disclosure).
  • Comply with applicable law.

How to report

Email [email protected] with the subject “Security vulnerability report”. Please include:

  • A description of the issue and its potential impact
  • Steps to reproduce (URLs, request/response details, proof-of-concept code or screenshots)
  • The account or workspace you used for testing
  • How you would like to be credited, if at all

If you need to share sensitive material, ask us for a secure channel and we will arrange one.

What to expect from us

  • Acknowledgement of your report within 3 business days.
  • Triage and an initial assessment within 10 business days, with a named contact.
  • Regular updates while we work on a fix, and notice when it is deployed.
  • We aim to fix confirmed high- and critical-severity issues as a priority and other confirmed issues within 90 days.
  • With your agreement, public credit on request once the issue is fixed.

We do not currently run a paid bug-bounty programme.

Coordinated disclosure

We ask that you give us 90 days from acknowledgement before publishing details of a vulnerability. If we need longer (for example because a fix depends on a third party) we will explain why and agree a date with you. If we do not respond within the timelines above, you may contact us again and, failing that, disclose responsibly.

Safe harbour

Research carried out in accordance with this policy is considered authorised. We will not pursue civil or criminal action, or make a complaint to law enforcement, against researchers who comply with it. If a third party initiates legal action against you for activity conducted under this policy, we will make it known that your actions were authorised. This safe harbour does not extend to activity outside the rules of engagement.

Contact

[email protected] · Stacker Software Ltd, 86–90 Paul Street, London EC2A 4NE, United Kingdom