Legal · Security policy

Security.

If you find a security vulnerability in GrowthSync, please report it to us directly. We will investigate all legitimate reports and work to resolve issues quickly.

Scope

In scope: app.growthsync.com, our API, authentication flows, data handling.

Out of scope: Third-party integrations (Instagram, TikTok, Stripe), our marketing site, denial of service, social engineering.

Ground rules

  • Do not access or modify other users’ data.
  • Do not run automated scanners against production.
  • Give us 90 days to fix before public disclosure.
  • Test against your own account only.

How to report

Email engineering@growthsync.com with a description of the vulnerability, steps to reproduce, and any supporting screenshots or proof-of-concept code.

We will acknowledge your report within 3 business days.

Severity levels

  • Critical — auth bypass, mass data exposure.
  • High — privilege escalation, data leak.
  • Medium / low — logic flaws, best-practice gaps.

Last updated: July 2026.