Security
Vulnerability Disclosure Policy
We take security seriously. If you've found a vulnerability in DialerBee, we want to hear from you.
How to Report
Email security@dialerbee.com with the details below. Do not open a public issue or disclose the vulnerability publicly before we've had a chance to address it.
What to Include
- Description of the vulnerability and its potential impact
- Steps to reproduce (including URLs, parameters, payloads if applicable)
- Affected component or service (e.g., API, agent desktop, admin portal)
- Your contact information for follow-up
- Any proof-of-concept code or screenshots
Our Commitment
24 hours
Acknowledge receipt of your report
48 hours
Provide initial assessment and severity classification
7 days
Provide a remediation timeline
90 days
Maximum disclosure window before you may publish
Scope
The following are in scope for responsible disclosure:
- DialerBee web application and agent desktop
- DialerBee REST API
- Authentication and authorization systems
- Multi-tenant isolation boundaries
- Recording storage and access controls
- Compliance engine logic
Out of Scope
- Social engineering attacks against DialerBee employees
- Denial of service (DoS/DDoS) attacks
- Physical security of offices or data centers
- Third-party services not operated by DialerBee
- Spam or phishing attempts
Safe Harbor
We will not take legal action against security researchers who discover and report vulnerabilities in good faith, following this policy. We consider security research conducted in accordance with this policy to be authorized, and we will work with you to understand and resolve the issue quickly.
For general security questions or to request our Security Overview, DPA, or penetration test summary:
security@dialerbee.com