Responsible Disclosure Policy
Version 1.6
Effective September 29, 2025
Version 1.6
Effective September 29, 2025
We are dedicated to maintaining the security and privacy of the Conveyor services and customer data. We welcome security researchers from the community who want to help us improve our products and services.
If you discover a security vulnerability, please give us the chance to fix it by emailing us at security@conveyor.com. Publicly disclosing a security vulnerability without informing us first puts the rest of the community at risk. When you notify us of a potential problem, we will work with you to make sure we understand the scope and cause of the issue.
Thank you for your work and interest in making the community safer and more secure!
Conveyor awards security researchers cash and prizes for reporting in scope vulnerabilities. Please email security@conveyor.com to report an issue.
If you would like to be eligible for a bounty, please read this carefully. We reserve the right to discontinue issuing bounties at any time. Bounties will be issued via bill.com and additional documentation may be required based on residence of the researcher.
We strive to reply to all reports within 72 hours. However, if you submit an out of scope report we may not be able to reply to all out of scope reports.
Doing any of the above will render you ineligible for cash bounties and prizes.
Only the following services are in-scope:
Please do not test or report issues with services not listed here, especially our marketing site www.conveyor.com.
The following types of reports/attacks are out of scope. Do not attempt them:
Researchers are listed here based on adherence to these program guidelines, professionalism, and significance or novelty of the issue(s) reported:
We may periodically update the scope and guidelines of our program so please check back here periodically.