Report security issues privately.
We appreciate good-faith security research. Please use the private SourcingOS contact channel so suspected vulnerabilities can be investigated before public disclosure.
How to report
Use the contact form and identify the request as a security report. Include the affected URL or feature, a concise description, reproduction steps, and the security impact you observed.
Please do
- Use test or your own account/data whenever possible.
- Stop testing if you encounter another person's private information.
- Give us a reasonable opportunity to investigate and remediate before public disclosure.
- Share the minimum evidence needed to reproduce the problem.
Please do not
- Access, alter, download or delete data that is not yours.
- Perform denial-of-service, destructive, high-volume, social-engineering, credential-stuffing or spam testing.
- Expose passwords, API keys, tokens, candidate records or other secrets in the initial report.
- Use a vulnerability to contact candidates, customers or third parties.
security.txt
SourcingOS also publishes a machine-readable security contact file for researchers and automated discovery.
Scope and safe-harbor note
This page describes the intended good-faith reporting process; it is not a blanket authorization for testing that violates law, third-party terms, privacy, availability, or other users' rights. When in doubt, report the concern without attempting further exploitation.