Responsible Disclosure Policy
Found a security bug in CommsOperator? Where to send it, what is in scope, what we ask you not to do, and what we promise back: a reply in 2 business days and no legal action for good-faith research.
- Version
- 1.0
- Effective
- 2026-08-26
- Last updated
- 2026-08-26
- Provider
- WomenTech LLC
We welcome reports from security researchers. Send them to office@commsoperator.com. The same address is published in /.well-known/security.txt. We do not run a paid bug bounty programme; we do acknowledge researchers publicly with their permission.
In scope
- The application and website at https://www.commsoperator.com
- The embeddable widgets and their public endpoints
- The public API endpoints, including the leads endpoint and the MCP server
- The desktop application and the browser extension distributed from our download page
Out of scope
- Third-party services we integrate with, such as Microsoft 365, OpenAI, or Stripe. Report those to their own programmes.
- Findings that require a compromised device, a malicious browser extension, or physical access.
- Reports produced only by an automated scanner without a demonstrated impact.
- Missing security headers, weak TLS ciphers, or rate-limit findings without a working exploit path.
- Social engineering of our team, our customers, or our providers.
- Denial of service, volumetric testing, and spam.
Rules of engagement
- Use only your own account and test data. Do not access, modify, or exfiltrate another customer's data; if you encounter it, stop and tell us.
- Do not degrade the service for others. No load testing, no automated scanning at volume.
- Give us reasonable time to fix an issue before publishing. We aim for 90 days and will tell you if we need longer and why.
- Do not demand payment in exchange for withholding a report.
What to expect from us
How to read this table: each row is one step in our handling of your report and the time we aim to hit.
| Step | Target |
|---|---|
| Acknowledgement of your report | 2 business days |
| Initial assessment and severity | 5 business days |
| Status update while we work | Every 10 business days |
| Fix for a critical issue | As fast as safely possible, usually days |
| Public credit, with your permission | On release of the fix |
If you follow this policy in good faith, we will not pursue legal action against you for your research, and we will say so in writing if a third party questions it.
Please include: what you found, where, a minimal reproduction, the impact you believe it has, and how you would like to be credited. Encrypted correspondence can be arranged on request.