Legal · Security policy
Security.
If you find a security vulnerability in GrowthSync, please report it to us directly. We will investigate all legitimate reports and work to resolve issues quickly.
Scope
In scope: app.growthsync.com, our API, authentication flows, data handling.
Out of scope: Third-party integrations (Instagram, TikTok, Stripe), our marketing site, denial of service, social engineering.
Ground rules
- Do not access or modify other users’ data.
- Do not run automated scanners against production.
- Give us 90 days to fix before public disclosure.
- Test against your own account only.
How to report
Email engineering@growthsync.com with a description of the vulnerability, steps to reproduce, and any supporting screenshots or proof-of-concept code.
We will acknowledge your report within 3 business days.
Severity levels
- Critical — auth bypass, mass data exposure.
- High — privilege escalation, data leak.
- Medium / low — logic flaws, best-practice gaps.