We take the security of Firstweek and our customers' data seriously. If you believe you have found a security vulnerability in our systems, we encourage you to report it to us responsibly. We will investigate all credible reports and work to resolve confirmed issues promptly.
How to report
Send a detailed report to [email protected]. Please include:
- A description of the vulnerability and the potential impact
- Step-by-step reproduction instructions
- Any relevant URLs, request/response payloads, or screenshots
- The type of issue (e.g. XSS, SQL injection, authentication bypass, data exposure)
We will acknowledge your report within 3 business days and provide an estimated timeline for resolution. We will keep you informed as we investigate and remediate.
Scope
The following are in scope for vulnerability reports:
- firstweek.app and all subdomains — the web application, API, and authentication flows
- Data isolation between workspaces (tenant separation)
- Authentication and authorization controls
- OAuth integration flows (Slack, GitHub, Google, Atlassian, Microsoft)
- Exposure of encrypted credentials or tokens
The following are out of scope:
- Denial of service attacks
- Social engineering or phishing of Firstweek staff
- Vulnerabilities in third-party services we depend on (report those directly to the vendor)
- Issues requiring physical access to our infrastructure
- Automated scanner output without proof of exploitability
Our commitments
- We will not pursue legal action against researchers who report in good faith under this policy
- We will not share your contact details with third parties without your permission
- We will credit researchers who responsibly disclose valid vulnerabilities, if they wish
- We ask that you give us reasonable time to remediate before any public disclosure
Contact
Security disclosures: [email protected]
General privacy questions: [email protected]