Vulnerability Disclosure Policy
Purple Crow is committed to protecting the security of our customers, employees, and systems. If you believe you've discovered a security vulnerability affecting our website or systems, we appreciate your help disclosing it to us responsibly.
How to Report
Email security@purplecrow.com with a description of the vulnerability, steps to reproduce it, and any relevant technical details (proof-of-concept, screenshots, or logs). Reports in English are preferred.
What to Expect
We will acknowledge your report within 5 business days and keep you informed as we investigate. We ask that you give us a reasonable amount of time to address the issue before disclosing it publicly.
Guidelines
• Don't access, modify, or delete data that isn't yours
• Don't take any action that could degrade or disrupt our services
• Don't run automated scans that generate significant traffic without prior authorization
• Only interact with accounts you own or have explicit permission to test
Safe Harbor
Purple Crow will not pursue legal action against individuals who discover and report vulnerabilities in good faith and in accordance with this policy.
This policy does not offer financial compensation for reports.