Responsible Vulnerability Disclosure

This page is for independent security researchers who want to report or investigate vulnerabilities on the SyncSign platform.

The information on this page is intended only for security researchers who are interested in reporting security vulnerabilities on SyncSign. If you are a SyncSign customer and have questions, contact our customer service team at help[at]sync-sign.com.

If you believe that you have discovered a security vulnerability on SyncSign, we strongly encourage you to inform us and to not disclose the vulnerability publicly.

Reporting a potential security vulnerability:

Privately send details of the vulnerability to SyncSign team by sending an email to dev[at]sync-sign.com

Please provide full details of the vulnerability, including:

  • Type of issue (buffer overflow, SQL injection, cross-site scripting, etc.)

  • Product and version that contains the bug, or URL

  • Service packs, security updates, or other updates for the product you have installed

  • Any special configuration required to reproduce the issue

  • Step-by-step instructions to reproduce the issue on a fresh install

  • Proof-of-concept or exploit code

  • Impact of the issue, including how an attacker could exploit the issue

SyncSign follows Coordinated Vulnerability Disclosure (CVD) and, to protect the ecosystem, we request that those reporting to us do the same.

We appreciate your assistance, and we review all reports and do our best to address the issues within the specified time frame.