01Our commitment
Echo (a trading name of ALLIN1.APP LTD) takes the security of our customers seriously. We welcome reports from security researchers and will work with you to understand and resolve any issue quickly.
We will acknowledge your report within 3 business days, keep you updated on our progress, and let you know when the issue is resolved.
02How to report
Email [email protected] with a clear description of the issue. Where possible, include the steps to reproduce, the affected URL or component, the potential impact, and any proof-of-concept material.
Please do not disclose the issue publicly until we have confirmed it is resolved. We will coordinate timing of any public disclosure with you.
03Scope
In scope: the echobrain.io marketing site, the Echo dashboard, the Echo Slack application (including its OAuth flow, scopes, and handling of Slack events and tokens), and the Echo agent and API services that support them.
Out of scope: the Slack platform itself and any other third-party service we integrate with. Please report those to the relevant provider (for example, Slack vulnerabilities go to Slack’s own security team). Also out of scope: denial-of-service (DoS/DDoS) attacks, volumetric or automated scanning that degrades the service, social engineering of our staff or customers, physical attacks, and spam.
04Safe harbour
If you make a good-faith effort to comply with this policy during your research, we will consider your activity authorised, we will not pursue or support legal action against you, and we will work with you to understand and resolve the issue.
Good faith means: you avoid privacy violations, data destruction, and service degradation; you only interact with accounts you own or have explicit permission to test; and you give us a reasonable time to remediate before any disclosure.
05Recognition
We do not currently operate a paid bug bounty programme. With your permission, we are happy to publicly credit researchers who responsibly disclose valid issues.