Security
Vulnerability Disclosure Policy
We take security seriously. If you've found a vulnerability in DialerBee, we want to hear from you.
Quick answer
What is the DialerBee vulnerability disclosure policy? It sets out how to report a security vulnerability to DialerBee and what happens next. Email security@dialerbee.com with a description of the vulnerability and its impact, steps to reproduce, the affected component, your contact information and any proof-of-concept, and do not disclose it publicly before we have had a chance to address it. We acknowledge receipt within 24 hours, give an initial assessment and severity classification within 48 hours, provide a remediation timeline within 7 days, and treat 90 days as the maximum disclosure window before you may publish. In scope: the web application and agent desktop, the REST API, authentication and authorization systems, multi-tenant isolation boundaries, recording storage and access controls, and the compliance engine.
How to Report
Email security@dialerbee.com with the details below. Do not open a public issue or disclose the vulnerability publicly before we've had a chance to address it.
What to Include
- Description of the vulnerability and its potential impact
- Steps to reproduce (including URLs, parameters, payloads if applicable)
- Affected component or service (e.g., API, agent desktop, admin portal)
- Your contact information for follow-up
- Any proof-of-concept code or screenshots
Our Commitment
Scope
The following are in scope for responsible disclosure:
- DialerBee web application and agent desktop
- DialerBee REST API
- Authentication and authorization systems
- Multi-tenant isolation boundaries
- Recording storage and access controls
- Compliance engine logic
Out of Scope
- Social engineering attacks against DialerBee employees
- Denial of service (DoS/DDoS) attacks
- Physical security of offices or data centers
- Third-party services not operated by DialerBee
- Spam or phishing attempts
Safe Harbor
We will not take legal action against security researchers who discover and report vulnerabilities in good faith, following this policy. We consider security research conducted in accordance with this policy to be authorized, and we will work with you to understand and resolve the issue quickly.
For general security questions or to request our Security Overview or DPA:
security@dialerbee.com