Skip to main content

Legal

Vulnerability Disclosure Policy

How to report a security issue in our products, what we will do with your report, and the rules we ask researchers to follow.

Effective: July 25, 2026Last Updated: July 25, 2026

We sell security, so we owe security researchers a clear way in. This policy explains what you may test, how to send us a report, and what SO Labs Inc. (“Ṣọ,” “we,” or “us”) will do in return. Send reports to privacy@soemailsecurity.com. A machine-readable version of these contact details is published at /.well-known/security.txt. This policy sits alongside our Terms of Service and our Privacy Policy.

01Scope

1.1 In scope

  • soemailsecurity.com, our main website and web app.
  • dashboard.cloudapi.soemailsecurity.com, the developer dashboard where API keys are created and managed.
  • api-service.soone.soemailsecurity.com, the Ṣọ Shield API.
  • The Ṣọ Chrome extension for Gmail and Outlook web.
  • The Ṣọ iOS app and the Ṣọ Android app.

Test against your own accounts and your own data. If you are not sure whether something is in scope, ask us first at privacy@soemailsecurity.com and we will tell you.

1.2 Out of scope

  • Third-party services. Systems we use but do not run, such as our hosting provider, our payment processor, and the mailbox providers our users connect. Report those to the provider. We are happy to help route a report if you are unsure who owns it.
  • Social engineering. Phishing, pretexting, or any other attempt to manipulate our staff, contractors, customers, or support channels.
  • Physical attacks. Anything involving our offices, our people, or physical access to hardware.
  • Denial of service. Volumetric testing, stress testing, resource exhaustion, or anything else that degrades the service for other users.
  • Raw scanner output. Automated tool results with no demonstrated impact. Show us what an attacker could actually do.
  • Missing headers and hardening suggestions. Reports about absent security headers, cookie flags, or configuration best practice with no working exploit path.

Out of scope means we will not treat it as a vulnerability report. It does not mean we do not want to hear it. Hardening suggestions are still welcome, they will simply be handled as ordinary feedback.

02How to Report

Email privacy@soemailsecurity.com. One issue per email, with a clear subject line. Please include:

  • Steps to reproduce. Enough detail that we can follow them from a clean state.
  • Impact. What an attacker could do with this, and who it affects.
  • The affected URL or endpoint. For the apps and the extension, tell us the version and the platform you tested on.
  • Any proof of concept. Requests, responses, a short script, a screenshot, or a screen recording.
  • How to reach you. And whether you want to be credited if we publish a thanks list.

Keep other people out of it. Do not include anyone else's personal data beyond the minimum needed to demonstrate the issue, and redact what you can. If you come across personal data by accident, stop testing, tell us in the report, and delete your copy. Do not access, download, or keep other users' data to prove a point. A single redacted example is always enough.

We read reports in English. We do not publish a PGP key today. If you need an encrypted channel, say so in your first email and we will arrange one before you send the details.

03Our Commitments

If you follow this policy, here is what you get from us:

  • Acknowledgement within 3 business days. A human confirms we have your report and have started looking.
  • An initial assessment within 10 business days. Whether we could reproduce it, how we rate the severity, whether we consider it in scope, and what we plan to do next.
  • Progress updates. We will keep you posted as the fix moves, and we will tell you when it has shipped. If we go quiet, chase us.
  • Credit if you want it. We will name you in a public thanks list, with the name or handle you choose. Tell us if you would rather stay anonymous, and we will leave you out.
  • A straight answer. If we decide not to fix something, we will say so and explain why, rather than leave the report open forever.

Business days mean Monday to Friday, excluding public holidays in Alberta, Canada.

04Safe Harbour

We will not pursue or support legal action against you for security research carried out in good faith under this policy. To rely on that, your research must:

  • Stay within the systems listed as in scope in Section 01.
  • Avoid privacy violations. Do not access, modify, delete, or retain any other user's data or mailbox.
  • Avoid degrading the service. No denial of service, no destructive testing, no mass automated traffic.
  • Use only accounts you own or have permission to test.
  • Stop as soon as you have enough to demonstrate the issue, then report it to us promptly.
  • Give us a reasonable chance to fix it before you tell anyone else. See Section 06.
  • Break no law, and use nothing you find for extortion, fraud, or personal gain.

If you follow this policy in good faith and we later think you crossed a line, we will treat it as an honest mistake and talk to you first. Contact us before you test if you are unsure whether an approach is acceptable, and we will give you an answer.

This is not a waiver of anyone else's rights. We can only speak for SO Labs Inc. This policy gives you no permission to test systems run by other companies, including our hosting provider, our payment processor, and the mailbox providers our users connect. It does not bind those companies, our customers, or any regulator or prosecutor, and it does not limit their rights. It also does not authorise you to break any law that applies to you.

Our Terms of Service set out the governing law and the dispute process for our site and products, and they apply here too.

05We Do Not Run a Paid Bug Bounty

There is no money on offer. We want to be plain about that up front rather than let anyone spend hours on a report and expect a cheque.

  • We do not pay rewards, bounties, or fees for vulnerability reports, including reports that lead to a fix.
  • We do not accept invoices for reports, and we will not negotiate a payment in exchange for details of an issue. A demand for payment before disclosure falls outside this policy and outside safe harbour.
  • What we do offer is a fast, honest response, credit in a public thanks list if you want it, and a clear account of what we changed.
  • If we start a paid programme, we will say so on this page. Until then, assume there is no payment.

06How We Handle Reports

6.1 Triage

We try to reproduce the issue first, then judge the real impact and set a severity. Severity decides priority. A serious issue that exposes user data or allows account takeover is worked on immediately, ahead of other engineering. Lower severity issues are scheduled into normal release work. If we cannot reproduce it, we will come back to you with what we tried before we close anything.

6.2 Disclosure timing

  • We ask you to hold off on public disclosure for 90 days from the date you report the issue.
  • We will move faster where we can. If the fix ships sooner, we are happy for you to publish sooner. Most of the time we would rather it were public once users are safe.
  • Please do not publish details of an unfixed issue, and agree the publication date with us so a fix is out and adopted first. Mobile app fixes can take longer because of app store review.
  • If we need longer than 90 days, we will tell you why and agree a new date with you rather than let the deadline pass in silence.
  • Where an issue has affected user data, we will notify affected users and any regulator we are required to notify, on the timelines the law sets.

These timings are a request, not a contract term. They exist so users are protected while a fix is built, not to keep problems quiet.

07Contact

What we hold, and what we do not. We follow GDPR-aligned privacy practices and we have completed Google CASA verification for our Gmail integration. We do not hold SOC 2, ISO 27001, or HIPAA compliance. If a certification matters for your purchase, ask us and we will tell you exactly where we stand rather than imply more than we have.

Thank you for reporting responsibly. Researchers who take the time to find and explain a flaw make the product safer for every person using it.