Responsible Disclosure Policy

At Current Software, the security of our platform and our customers' data is a top priority. We welcome and appreciate reports from security researchers and the broader community who help us identify potential vulnerabilities.

How to Report

If you believe you've found a security vulnerability, please email us at security@currentsoftware.com. Include as much detail as possible:

What to Expect

Scope

The following are in scope for responsible disclosure:

The following are out of scope:

Guidelines

We ask that you:

Safe Harbor

If you conduct security research in accordance with this policy, we consider your research to be authorized. We will not pursue legal action against you for good-faith efforts to identify and report vulnerabilities. We ask that you contact us before engaging in any activity that might be inconsistent with or unaddressed by this policy.

Rewards

We do not currently operate a formal bug bounty program. However, we may offer recognition or rewards at our discretion for particularly impactful reports.

Credit

With your permission, we are happy to publicly acknowledge your contribution. Let us know in your report how you would like to be credited.

Last updated: May 2026