TotalCtrl holds business-critical data for the organizations that use it, so
we would much rather hear about a security problem from you than discover it
later. If you have found a vulnerability in our platform, we want your
report, and this page tells you how to send it and the terms under which
you are welcome to look for one.
We welcome reports from anyone. You do not need an account, an invitation,
or a prior relationship with us, and you will never be charged for the time
you spend telling us about a flaw.
The URL, endpoint, or feature affected, and the type of issue.
Steps to reproduce it, in enough detail that we can follow them. A short
video or a request/response capture is often the fastest thing to send.
What an attacker could actually do with it, and any preconditions
(for example, whether it needs an authenticated account, or a particular
role).
Any account identifiers, timestamps, or IP addresses you used, so we can
find your activity in our logs and separate it from real attacks.
How you would like to be credited, if you would like to be.
Write in English if you can. Reports in other languages are still welcome and
we will translate them.
Safe harbor
If you make a good-faith effort to comply with this policy during your
research, we will treat your work as authorized. Specifically:
We will not bring legal action against you, or refer you for
prosecution, in relation to your research.
We will not report your activity to law enforcement, and if a third
party brings action against you for research conducted under this policy,
we will make it known that your work was authorized.
We will treat your testing as authorized conduct under the Computer
Fraud and Abuse Act, the Digital Millennium Copyright Act's
anti-circumvention provisions, and comparable laws elsewhere, and we
waive any claim under our Terms of Service that would otherwise prohibit
it.
We will work with you to understand your report quickly, and will not
treat an honest mistake in your testing as bad faith.
This authorization covers your research only, and it cannot bind anyone but
us — it does not extend to systems operated by our subprocessors or by other
third parties. If you are unsure whether something is covered, ask us
first at security@totalctrl.app
and we will answer.
Rules of engagement
To stay within this policy, please:
Use your own data. Create a free workspace and test
against that. Do not access, modify, or download data belonging to anyone
else.
Stop when you have proof. Once you can demonstrate a
vulnerability, stop — do not enumerate further records, escalate for its
own sake, or maintain access.
Tell us immediately if you encounter other people's data,
stop testing, and do not save, copy, or share it.
Do not degrade the service. Keep automated traffic to a
reasonable rate and never test in a way that affects other users'
availability.
Do not use a vulnerability beyond what is needed to confirm it
— no persistence, no pivoting, no backdoors, and remove any test artifacts
you leave behind.
Give us time to fix it. Please keep the issue
confidential until we have shipped a fix, and coordinate publication with
us. We will not ask you to stay quiet indefinitely: if we have not fixed
an issue within 90 days of confirming it, you are free to
publish, and we would appreciate a heads-up first.
Do not extort us. Withholding details pending payment,
or threatening publication to force one, is not good-faith research and
the safe harbor above does not cover it.
Questions about this policy, or about whether something is covered, go to
security@totalctrl.app. If you
are a customer reporting suspected unauthorized use of your own account,
email us at the same address and say so in the subject line — we prioritize
those.