Responsible Disclosure Policy

Last reviewed: September 30, 2026

At Click2Mail, we are committed to the security of our systems and the protection of our customers' data. We value the contributions of independent security researchers and have established this policy to provide clear guidelines for reporting potential vulnerabilities and to outline our commitments to those who assist us.

Guiding Principles

Our RDP is guided by the following principles:

  • Collaboration: We believe in working with the security community to create a more secure environment for everyone.
  • Transparency: We are committed to being transparent about our security practices and how we handle vulnerability reports.
  • Protection: We will not take legal action against researchers who discover and report vulnerabilities in good faith and in accordance with this policy.

Reporting a Vulnerability

If you believe you have discovered a security vulnerability in a Click2Mail product or service, please report it to us as soon as possible.

  • Reporting Channel: Please send a detailed report to [email protected] .
  • Report Contents: To help us validate and address the vulnerability efficiently, please include the following in your report:
    • A detailed description of the vulnerability, including the steps to reproduce it.
    • The affected product, service, or URL.
    • Any proof-of-concept code, scripts, or screenshots that demonstrate the issue.
    • Your contact information for follow-up questions.

Scope of the Policy

This policy applies to all publicly accessible Click2Mail services and applications.

In-Scope Systems

Out-of-Scope Activities

The following activities are strictly prohibited:

  • Denial of Service (DoS) or Distributed Denial of Service (DDoS) attacks.
  • Physical attacks against Click2Mail employees, offices, or data centers.
  • Social engineering of Click2Mail employees, contractors, or customers.
  • Any testing that could disrupt services for our users.

Compensation and Recognition

Click2Mail does not currently operate a formal bug bounty program. Therefore, we do not offer monetary rewards for vulnerability reports.

However, we believe in recognizing the valuable contributions of security researchers. For confirmed, critical vulnerabilities, we may offer a non-monetary token of our appreciation, such as a public acknowledgment on our website (with your permission).

Safe Harbor

This policy serves as a "Safe Harbor" statement. We will not initiate legal action against any researcher for security research that is conducted in accordance with this policy and in good faith. We consider research conducted under this policy to be:

  • Authorized in accordance with the Computer Fraud and Abuse Act (CFAA) and other applicable computer crime laws.
  • Exempt from our Terms of Service provisions that would otherwise prohibit such research.

We will work with you to understand and quickly resolve issues, and we will not engage in legal action as long as you make a good faith effort to avoid privacy violations, destruction of data, and interruption or degradation of our services.

Our Commitment to You

If you report a vulnerability in compliance with this policy, we commit to the following:

  • Acknowledgement: We will acknowledge receipt of your report in a timely manner.
  • Communication: We will maintain an open line of communication with you throughout the validation and remediation process.
  • Resolution: We will make every effort to address the vulnerability as quickly as possible.

Thank you for helping us keep Click2Mail secure.