socbox

Security

Security at socbox.

We build a security platform; we hold ourselves to the same standards we ask of our customers. This page covers how to report a vulnerability, what we promise in return, and how we handle the data you trust us with.

Responsible disclosure

If you believe you have found a security vulnerability in any socbox product, please report it to security@socbox.cloud.

We acknowledge, triage and fix reports as fast as we can, with critical issues jumping the queue — we're deliberately not publishing clock-time commitments until we can staff them. Researchers who report in good faith are protected by our safe-harbor policy (no legal action).

In scope

Out of scope

Machine-readable disclosure metadata follows RFC 9116 at /.well-known/security.txt.

Data handling

Compliance