Vulnerability disclosure
Last updated: 6 July 2026
We want to hear about security problems in Ease. If you have found a vulnerability in our apps, SDKs, website, or API, this page explains how to report it and what happens next.
How to report
Email security@securegroupchat.com with enough detail to reproduce the issue: the affected component and version, the steps you took, and the impact you observed. A proof of concept helps. If a report contains sensitive detail, say so and we will arrange an encrypted channel.
Scope
- The Ease apps for web, iOS, macOS, Android, and Windows.
- The Ease SDKs.
- securegroupchat.com and docs.securegroupchat.com.
- The Ease API and its authentication surface.
Out of scope
- Denial-of-service and volumetric attacks, and any testing that degrades the service for others.
- Social engineering of our team, customers, or vendors, and physical attacks.
- Reports from automated scanners without a demonstrated, exploitable impact.
- Missing best-practice headers or configuration with no concrete security impact.
Guidelines
- Use only your own test accounts and data. Do not access, modify, or delete data that is not yours.
- Stop and report as soon as you confirm a vulnerability; do not pivot further into our systems.
- Give us a reasonable time to remediate before any public disclosure, and coordinate the timing with us.
Safe harbor
We will not pursue or support legal action against researchers who act in good faith under this policy: who stay in scope, respect the guidelines above, and avoid privacy violations and service disruption. If a third party brings action against you for such research, we will make our authorization known.
What to expect
We aim to acknowledge a report within three business days, confirm the issue and its severity after triage, and keep you updated through remediation. We are grateful for reports and will credit reporters who want it. Ease does not run a paid bounty program at this time.