Security
Last updated: July 2026
Reporting a vulnerability
We take the security of our customers’ building-safety and financial records seriously. If you believe you have found a vulnerability, we welcome a private, coordinated disclosure before any public write-up.
Email us at [email protected] or use our contact form. Please include enough detail to reproduce the issue, and give us a reasonable window to investigate and fix before disclosing publicly. We will acknowledge your report and keep you updated through to a resolution.
Acknowledgements
With thanks to the researchers who have reported issues responsibly and helped us keep the platform safe.
- Nick, GreySurface (July 2026)Reference GS-2026-1625-5. Reported a row-level security misconfiguration that allowed unauthenticated read access to the invoices API. Fixed the same day; only demonstration data was affected.