Vulnerability Disclosure Program

CallRail is committed to ensuring the security and privacy of our services and customer information. As part of this commitment, we encourage security researchers to contact us to report any potential weaknesses identified in any of our products, systems, and/or assets. This program isn’t intended to represent a public bug bounty program and we make no offers of reward or compensation for submitting potential issues.

Guidelines

Potential vulnerabilities or weaknesses can be disclosed in accordance with the following guidelines:

  1. Submit a clear, concise description of the issues, including proof-of-concept (POC) URL and details of the system(s) where testing was performed
  2. Submit a clear and concise description of the steps needed to reproduce the issue
  3. Submit issues through the form instead of making them public (e.g., on message boards, mailing lists, or other forums)
  4. Wait to receive notification of resolution prior to disclosing any issues to third parties
  5. As part of your research don't
  1. engage in any activity that may cause an outage, stop services, and/or cause disruption to CallRail's services
  2. cause harm to CallRail, its customers, shareholders, partners, or employees
  3. engage in unlawful activities (domestic and international)
  4. engage in activities that violate regulations (domestic and international)
  5. store, share, compromise or destroy any CallRail or CallRail customer data. If you encounter any protected information (PCI, PHI, PII, etc.) you are required to stop your testing and immediately contact us, legal@callrail.com
  6. any fraudulent activity or complete fraudulent financial transactions as part of your testing/research