Security

Vulnerability Disclosure Policy

We take security seriously. If you've found a vulnerability in DialerBee, we want to hear from you.

How to Report

Email security@dialerbee.com with the details below. Do not open a public issue or disclose the vulnerability publicly before we've had a chance to address it.

What to Include

  • Description of the vulnerability and its potential impact
  • Steps to reproduce (including URLs, parameters, payloads if applicable)
  • Affected component or service (e.g., API, agent desktop, admin portal)
  • Your contact information for follow-up
  • Any proof-of-concept code or screenshots

Our Commitment

24 hours
Acknowledge receipt of your report
48 hours
Provide initial assessment and severity classification
7 days
Provide a remediation timeline
90 days
Maximum disclosure window before you may publish

Scope

The following are in scope for responsible disclosure:

  • DialerBee web application and agent desktop
  • DialerBee REST API
  • Authentication and authorization systems
  • Multi-tenant isolation boundaries
  • Recording storage and access controls
  • Compliance engine logic

Out of Scope

  • Social engineering attacks against DialerBee employees
  • Denial of service (DoS/DDoS) attacks
  • Physical security of offices or data centers
  • Third-party services not operated by DialerBee
  • Spam or phishing attempts

Safe Harbor

We will not take legal action against security researchers who discover and report vulnerabilities in good faith, following this policy. We consider security research conducted in accordance with this policy to be authorized, and we will work with you to understand and resolve the issue quickly.

For general security questions or to request our Security Overview, DPA, or penetration test summary:

security@dialerbee.com