Legal
Vulnerability Disclosure Policy
How security researchers can responsibly report vulnerabilities in SparrowHawk CRM.
Effective: July 13, 2026
Last updated: July 13, 2026
- v1.0 · July 13, 2026Initial Vulnerability Disclosure Policy.
1. Welcome
SparrowHawk CRM LLC welcomes reports from security researchers acting in good faith. This policy explains what SparrowHawk CRM LLC considers in-scope, what researchers may and may not do while testing, how to report findings, and how SparrowHawk CRM LLC will respond.
2. Scope
The following are in scope:
- the SparrowHawk CRM production web application and its public APIs
- authenticated flows accessed through a researcher's own test account
- public marketing pages and forms operated by SparrowHawk CRM LLC
3. Out of Scope
The following are out of scope and researchers must not test against them:
- systems operated by third-party subprocessors (Stripe, Google, Cloudflare, Supabase, and others listed on the Subprocessor List)
- Customer-owned accounts, data, or content unless the researcher owns the affected Customer account
- physical facilities, social engineering, and vishing against SparrowHawk CRM LLC personnel
- denial-of-service, resource-exhaustion, and stress testing
- reports based solely on missing best-practice headers or theoretical issues without a demonstrable impact
- findings that require compromising a Customer account the researcher does not control
4. Rules of Engagement
Researchers agree to:
- test only against their own accounts and data
- stop testing and report immediately on encountering another party's data
- avoid destructive actions and privacy violations
- avoid degrading service availability
- use minimum necessary proof-of-concept payloads
- give SparrowHawk CRM LLC a reasonable opportunity to remediate before public disclosure
5. Safe Harbor
SparrowHawk CRM LLC will not pursue legal action against researchers who make a good-faith effort to comply with this policy, whose testing is limited to the in-scope systems, and who avoid privacy violations and service disruption. If a third party initiates legal action against a researcher who has complied with this policy, SparrowHawk CRM LLC will make its position known that the activity was authorized.
Note for legal counsel: safe-harbor language should be reviewed against the Computer Fraud and Abuse Act, similar state laws, and any applicable non-U.S. legislation (including the EU Cyber Resilience Act) before public reliance.
6. How to Report
Send reports to security@sparrowhawkcrm.com (or support@sparrowhawkcrm.com if the security address is not yet monitored). Include:
- a clear description of the issue and the affected component
- reproduction steps
- impact assessment
- any relevant logs, screenshots, or minimal proof-of-concept code
- contact information for follow-up
7. Our Response
SparrowHawk CRM LLC will:
- acknowledge receipt within a reasonable time
- triage the report and communicate expected remediation timelines
- coordinate on public disclosure timing where appropriate
- close out the report when remediation is complete
8. Acknowledgement
With the researcher's permission, SparrowHawk CRM LLC may publicly acknowledge contributors who report valid, in-scope findings. SparrowHawk CRM LLC does not currently operate a paid bug bounty and any acknowledgement is discretionary.
