Report a vulnerability
The security of our customers' accounting data is our top priority. If you have found a vulnerability in Contabli, please report it to us confidentially.
Please send reports to: nizar.bechir@beytp.com
Please
- describe the vulnerability so that we can reproduce it (affected address, steps, expected and actual behaviour);
- only access your own test accounts, never other people's data; stop as soon as you see someone else's data and tell us;
- disclose only after we have fixed the issue, or after 90 days in agreement with us.
We
- confirm receipt within three working days and keep you informed;
- take no legal action against reports that follow these rules;
- credit you as the finder after the fix if you wish.
Not allowed
- Denial-of-service and load tests, spam, social engineering, physical attacks and automated mass scanning.
- Accessing, changing or deleting other people's data.