We appreciate responsible security research that helps protect HelloGrowthCRM customers. If you believe you have found a security vulnerability, please report it to us privately before public disclosure.
How to report
Email security@hellogrowthcrm.com with the subject line "Security vulnerability" and include a clear description, steps to reproduce, affected URLs or components, and any proof-of-concept you are comfortable sharing. Encrypt sensitive details if your organization requires it; mention that in the message and we will coordinate a secure channel if needed.
Scope
Reports should concern the HelloGrowthCRM product, APIs, and official web properties operated by Soor LLC. Do not access data that does not belong to you, degrade production services, or perform destructive testing without prior agreement.
What to expect
We aim to acknowledge valid reports promptly, investigate in good faith, and remediate serious issues according to severity. We may credit researchers when a fix ships if you would like public recognition. This page does not constitute a bug bounty program or guaranteed payment; commercial bounty terms, if offered, will be published separately.
For general security and compliance documentation, see the Trust Center.