TotalCtrl
Subprocessors Vulnerability Disclosure Bug Bounty Compliance

Vulnerability Disclosure Policy

Last updated: August 2026

Report a vulnerability: security@totalctrl.app
We acknowledge every report within 3 business days. Machine-readable version: /.well-known/security.txt

TotalCtrl holds business-critical data for the organizations that use it, so we would much rather hear about a security problem from you than discover it later. If you have found a vulnerability in our platform, we want your report, and this page tells you how to send it and what we will do with it.

We welcome reports from anyone. You do not need an account, an invitation, or a prior relationship with us, and you will never be charged for the time you spend telling us about a flaw.

How to report

Email security@totalctrl.app. Please include as much of the following as you have:

  • The URL, endpoint, or feature affected, and the type of issue.
  • Steps to reproduce it, in enough detail that we can follow them. A short video or a request/response capture is often the fastest thing to send.
  • What an attacker could actually do with it, and any preconditions (for example, whether it needs an authenticated account, or a particular role).
  • Any account identifiers, timestamps, or IP addresses you used, so we can find your activity in our logs and separate it from real attacks.
  • How you would like to be credited, if you would like to be.

Write in English if you can. Reports in other languages are still welcome and we will translate them.

What we commit to

  • Acknowledgment within 3 business days of your report reaching us — from a person, not an autoresponder.
  • An assessment within 10 business days: whether we have reproduced the issue, how we rate its severity, and what we intend to do.
  • Progress updates at least every 14 days while the issue is open, without you having to ask.
  • Notice when it is fixed, and an offer to have you verify the fix.
  • Credit where you want it. We will name you in our acknowledgments, or keep your report anonymous — your choice, and we will ask before publishing anything.

We aim to remediate critical issues within 30 days of confirming them. Where a fix will take longer, we will tell you why and give you a target date rather than letting the thread go quiet.

Safe harbor

If you make a good-faith effort to comply with this policy during your research, we will treat your work as authorized. Specifically:

  • We will not bring legal action against you, or refer you for prosecution, in relation to your research.
  • We will not report your activity to law enforcement, and if a third party brings action against you for research conducted under this policy, we will make it known that your work was authorized.
  • We will treat your testing as authorized conduct under the Computer Fraud and Abuse Act, the Digital Millennium Copyright Act's anti-circumvention provisions, and comparable laws elsewhere, and we waive any claim under our Terms of Service that would otherwise prohibit it.
  • We will work with you to understand your report quickly, and will not treat an honest mistake in your testing as bad faith.

This authorization covers your research only, and it cannot bind anyone but us — it does not extend to systems operated by our subprocessors or by other third parties. If you are unsure whether something is in scope, ask us first at security@totalctrl.app and we will answer.

Scope

In scope:

  • totalctrl.app and its subdomains, including www.totalctrl.app and api.totalctrl.app.
  • The TotalCtrl web application and its public REST API.
  • The TotalCtrl mobile applications.
  • Customer-facing pages we serve on our own infrastructure, such as Help Centers, Client Portals, and public boards — including where a customer has pointed their own domain at them.

Out of scope:

  • Systems and services operated by third parties, including our subprocessors. Report those to the party that runs them.
  • Denial of service, volumetric testing, and anything else whose method is to degrade the service for other people.
  • Social engineering, phishing, or physical attacks against our staff, users, or offices.
  • Findings that are only the output of an automated scanner, with no demonstrated impact.
  • Missing hardening headers, cookie flags, TLS configuration preferences, and similar best-practice gaps, unless you can show a concrete exploit.
  • Software version disclosure, and vulnerabilities in third-party dependencies for which no working exploit against TotalCtrl is shown.
  • Email deliverability configuration (SPF, DKIM, DMARC) on domains that do not send our mail.
  • Self-inflicted issues that require a victim to paste code into their own browser console, or to install a malicious extension.
  • Reports about our own security-policy choices without an accompanying vulnerability. We will read them, but they are not disclosures.

Rules of engagement

To stay within this policy, please:

  • Use your own data. Create a free workspace and test against that. Do not access, modify, or download data belonging to anyone else.
  • Stop when you have proof. Once you can demonstrate a vulnerability, stop — do not enumerate further records, escalate for its own sake, or maintain access.
  • Tell us immediately if you encounter other people's data, stop testing, and do not save, copy, or share it.
  • Do not degrade the service. Keep automated traffic to a reasonable rate and never test in a way that affects other users' availability.
  • Do not use a vulnerability beyond what is needed to confirm it — no persistence, no pivoting, no backdoors, and remove any test artifacts you leave behind.
  • Give us time to fix it. Please keep the issue confidential until we have shipped a fix, and coordinate publication with us. We will not ask you to stay quiet indefinitely: if we have not fixed an issue within 90 days of confirming it, you are free to publish, and we would appreciate a heads-up first.
  • Do not extort us. Withholding details pending payment, or threatening publication to force one, is not good-faith research and the safe harbor above does not cover it.

Rewards

This policy is about getting the report to us, and it carries no payment requirement in either direction. We do run a separate bug bounty program under which qualifying reports may be rewarded — reporting here is how you enter it, and you never have to ask about money to be taken seriously.


Questions about this policy, or about whether something is in scope, go to security@totalctrl.app. If you are a customer reporting suspected unauthorized use of your own account, email us at the same address and say so in the subject line — we prioritize those.

← Back to TotalCtrl  ·  Privacy Policy  ·  Terms & Conditions