Legal

Vulnerability Disclosure Policy

How security researchers can responsibly report vulnerabilities in SparrowHawk CRM.

Effective: July 13, 2026

Last updated: July 13, 2026

Version
v1.0
Effective
July 13, 2026
Last Updated
July 13, 2026

1. Welcome

SparrowHawk CRM LLC welcomes reports from security researchers acting in good faith. This policy explains what SparrowHawk CRM LLC considers in-scope, what researchers may and may not do while testing, how to report findings, and how SparrowHawk CRM LLC will respond.

2. Scope

The following are in scope:

  • the SparrowHawk CRM production web application and its public APIs
  • authenticated flows accessed through a researcher's own test account
  • public marketing pages and forms operated by SparrowHawk CRM LLC

3. Out of Scope

The following are out of scope and researchers must not test against them:

  • systems operated by third-party subprocessors (Stripe, Google, Cloudflare, Supabase, and others listed on the Subprocessor List)
  • Customer-owned accounts, data, or content unless the researcher owns the affected Customer account
  • physical facilities, social engineering, and vishing against SparrowHawk CRM LLC personnel
  • denial-of-service, resource-exhaustion, and stress testing
  • reports based solely on missing best-practice headers or theoretical issues without a demonstrable impact
  • findings that require compromising a Customer account the researcher does not control

4. Rules of Engagement

Researchers agree to:

  • test only against their own accounts and data
  • stop testing and report immediately on encountering another party's data
  • avoid destructive actions and privacy violations
  • avoid degrading service availability
  • use minimum necessary proof-of-concept payloads
  • give SparrowHawk CRM LLC a reasonable opportunity to remediate before public disclosure

5. Safe Harbor

SparrowHawk CRM LLC will not pursue legal action against researchers who make a good-faith effort to comply with this policy, whose testing is limited to the in-scope systems, and who avoid privacy violations and service disruption. If a third party initiates legal action against a researcher who has complied with this policy, SparrowHawk CRM LLC will make its position known that the activity was authorized.

Note for legal counsel: safe-harbor language should be reviewed against the Computer Fraud and Abuse Act, similar state laws, and any applicable non-U.S. legislation (including the EU Cyber Resilience Act) before public reliance.

6. How to Report

Send reports to security@sparrowhawkcrm.com (or support@sparrowhawkcrm.com if the security address is not yet monitored). Include:

  • a clear description of the issue and the affected component
  • reproduction steps
  • impact assessment
  • any relevant logs, screenshots, or minimal proof-of-concept code
  • contact information for follow-up

7. Our Response

SparrowHawk CRM LLC will:

  • acknowledge receipt within a reasonable time
  • triage the report and communicate expected remediation timelines
  • coordinate on public disclosure timing where appropriate
  • close out the report when remediation is complete

8. Acknowledgement

With the researcher's permission, SparrowHawk CRM LLC may publicly acknowledge contributors who report valid, in-scope findings. SparrowHawk CRM LLC does not currently operate a paid bug bounty and any acknowledgement is discretionary.