Vulnerability disclosure policy

Effective September 23, 2026

If you find a security problem in UplevelRE, please tell us. We read every report and work with you until it is fixed.

How to report

Email [email protected] with a subject line that starts with “Security:”. Please don't open a public issue or report it through a support conversation. Include what you can:

  • the affected URL, endpoint, or app;
  • steps to reproduce, and what an attacker could gain;
  • any proof of concept, logs, or screenshots;
  • how you would like to be credited, if at all.

What happens next

  • We acknowledge your report within 2 business days.
  • We confirm or rule out the issue within 7 days.
  • We keep you updated until it is fixed, and tell you when it is.
  • We fix confirmed issues in production within 7 days for critical severity, 30 days for high, and 90 days for medium. Low-severity fixes ship in the next scheduled release.
  • With your permission, we credit you once the fix is live.

We don't offer payment for reports.

In scope

  • uplevelre.com and app.uplevelre.com
  • api.uplevelre.com, including the REST API and the MCP server
  • Websites and landing pages published with UplevelRE, on uplevel-sites.com or a customer's own domain. Only the parts UplevelRE serves are in scope, not the content a customer adds.
  • Email UplevelRE sends and receives, including lead email addresses

Out of scope

  • Services we use but don't run, such as Google, Stripe, or Telnyx. Report those to the vendor.
  • Denial of service, load testing, spam, and social engineering of anyone
  • Physical attacks on offices or data centers
  • Scanner output with no demonstrated impact, such as a missing header or a version number

Rules for testing

  • Use only accounts and workspaces you own, or that you have permission to use.
  • Stop as soon as you reach someone else's data. Don't keep, share, or change it, and tell us what you saw.
  • Don't degrade the service for other people.
  • Give us reasonable time to fix the issue before you disclose it. We'll agree a date with you.

If you follow these rules in good faith, we will treat your research as authorized, we will not pursue legal action against you for it, and we will say so if anyone else asks.

Related

Our security.txt lists this contact in a standard format. Our Privacy Policy explains how we handle personal information, and our sub-processor list names the companies that process it for us.