Report a Security Vulnerability

Ssemble welcomes reports from security researchers acting in good faith. If you believe you have found a security vulnerability in our products or infrastructure, please tell us — we will investigate, fix what needs fixing, and keep you informed.

How to report

Email support@ssemble.com with “Security” in the subject line. The most useful report tells us the affected URL or endpoint, the steps to reproduce the issue, and the impact you observed. Screenshots or a short screen recording help.

We will acknowledge your report and let you know what we find.

Rewards

We do not operate a paid bug bounty program and we do not offer monetary rewards for vulnerability reports. We review every report we receive regardless.

Testing guidelines

When researching, please:

  • Give us a reasonable window to remediate before disclosing publicly.
  • Use only accounts you own. Do not access, modify, or exfiltrate other people’s data.
  • Avoid anything that degrades service for our users, such as denial-of-service testing, spam, or automated scanning at volume.
  • Do not use social engineering, phishing, or physical attacks against our staff, customers, or vendors.

Research conducted in line with these guidelines is considered authorized, and we will not pursue action over it.

Out of scope

Reports that describe theoretical issues with no demonstrated impact, output of automated scanners without validation, missing hardening headers on their own, best-practice suggestions with no exploit path, and vulnerabilities in third-party services we do not operate.

Machine-readable contact information: /.well-known/security.txt