Security & Vulnerability Reporting
Security & Vulnerability Reporting
Last updated: 6 July 2026
SynaBot takes the security of our platform and the safety of our users seriously. We welcome reports from security researchers and users who identify potential vulnerabilities.
How to report
Email security@synabot.ai with:
- A clear description of the issue and its potential impact;
- Steps to reproduce (URLs, request payloads, screenshots);
- Your name or handle if you would like credit.
We aim to acknowledge security reports within 1 business day and to provide an initial assessment within 7 days.
Safe harbour
If you make a good-faith effort to comply with this policy, we will not pursue or support legal action against you for your research. Please:
- Only test against your own accounts or accounts you have explicit permission to test;
- Do not access, modify or destroy other users' data;
- Do not run automated scans that degrade the Service for other users;
- Give us a reasonable time to remediate before any public disclosure.
Out of scope
- Reports produced solely by automated scanners without a demonstrable impact;
- Missing security headers or best-practice recommendations with no exploit path;
- Social engineering of SynaBot staff, customers or vendors;
- Denial-of-service attacks and physical attacks on infrastructure;
- Issues in third-party services (e.g. Paddle) — please report those to the vendor directly.
Data breach notifications
If we determine that personal data has been affected by a security incident, we will notify affected users and, where required, the relevant regulator, in line with applicable law and our Privacy Notice.
Contact
SynaBot Inc., 16192 Coastal Highway, Lewes, Delaware 19958, USA — security@synabot.ai.
