Skip to content

Legal

Vulnerability Disclosure Policy

Effective 29 June 2026

This policy describes how to report security vulnerabilities in Echo and what you can expect from us in return.

01Our commitment

Echo (a trading name of ALLIN1.APP LTD) takes the security of our customers seriously. We welcome reports from security researchers and will work with you to understand and resolve any issue quickly.

We will acknowledge your report within 3 business days, keep you updated on our progress, and let you know when the issue is resolved.

02How to report

Email [email protected] with a clear description of the issue. Where possible, include the steps to reproduce, the affected URL or component, the potential impact, and any proof-of-concept material.

Please do not disclose the issue publicly until we have confirmed it is resolved. We will coordinate timing of any public disclosure with you.

03Scope

In scope: the echobrain.io marketing site, the Echo dashboard, the Echo Slack application (including its OAuth flow, scopes, and handling of Slack events and tokens), and the Echo agent and API services that support them.

Out of scope: the Slack platform itself and any other third-party service we integrate with. Please report those to the relevant provider (for example, Slack vulnerabilities go to Slack’s own security team). Also out of scope: denial-of-service (DoS/DDoS) attacks, volumetric or automated scanning that degrades the service, social engineering of our staff or customers, physical attacks, and spam.

04Safe harbour

If you make a good-faith effort to comply with this policy during your research, we will consider your activity authorised, we will not pursue or support legal action against you, and we will work with you to understand and resolve the issue.

Good faith means: you avoid privacy violations, data destruction, and service degradation; you only interact with accounts you own or have explicit permission to test; and you give us a reasonable time to remediate before any disclosure.

05Recognition

We do not currently operate a paid bug bounty programme. With your permission, we are happy to publicly credit researchers who responsibly disclose valid issues.