Report privately first. Email info@youragencydesk.com with a short description and a safe way to contact you. Do not include credentials, client records, or sensitive exploit output in the first message.
Helpful report details
- The affected URL or feature.
- The security impact and conditions required.
- Safe, minimal reproduction steps using an account and data you are authorized to test.
- Whether you believe active exploitation or exposed data is involved.
Research boundaries
- Do not access, modify, download, retain, or disclose another person's or agency's data.
- Do not use social engineering, phishing, denial-of-service, automated traffic that degrades service, or physical attacks.
- Do not test third-party services outside YourAgencyDesk's control.
- Stop immediately and report the issue if you encounter customer information.
- Allow reasonable time for investigation and remediation before any public disclosure.
Our process
Reports are triaged for reproducibility, scope, and impact. We may request additional information, coordinate remediation, and ask the reporter to verify the fix. Response times vary by complexity and severity; this page does not promise a fixed resolution deadline.
No bounty program
YourAgencyDesk does not currently operate a paid bug-bounty program. This policy is not permission to violate law, access data without authorization, or disrupt the service.
Machine-readable contact information is available at /.well-known/security.txt.