TotalCtrl
Subprocessors Vulnerability Disclosure Compliance

Vulnerability Disclosure Policy

Last updated: August 2026

Report a vulnerability: security@totalctrl.app
Machine-readable version: /.well-known/security.txt

TotalCtrl holds business-critical data for the organizations that use it, so we would much rather hear about a security problem from you than discover it later. If you have found a vulnerability in our platform, we want your report, and this page tells you how to send it and the terms under which you are welcome to look for one.

We welcome reports from anyone. You do not need an account, an invitation, or a prior relationship with us, and you will never be charged for the time you spend telling us about a flaw.

How to report

Email security@totalctrl.app. Please include as much of the following as you have:

  • The URL, endpoint, or feature affected, and the type of issue.
  • Steps to reproduce it, in enough detail that we can follow them. A short video or a request/response capture is often the fastest thing to send.
  • What an attacker could actually do with it, and any preconditions (for example, whether it needs an authenticated account, or a particular role).
  • Any account identifiers, timestamps, or IP addresses you used, so we can find your activity in our logs and separate it from real attacks.
  • How you would like to be credited, if you would like to be.

Write in English if you can. Reports in other languages are still welcome and we will translate them.

Safe harbor

If you make a good-faith effort to comply with this policy during your research, we will treat your work as authorized. Specifically:

  • We will not bring legal action against you, or refer you for prosecution, in relation to your research.
  • We will not report your activity to law enforcement, and if a third party brings action against you for research conducted under this policy, we will make it known that your work was authorized.
  • We will treat your testing as authorized conduct under the Computer Fraud and Abuse Act, the Digital Millennium Copyright Act's anti-circumvention provisions, and comparable laws elsewhere, and we waive any claim under our Terms of Service that would otherwise prohibit it.
  • We will work with you to understand your report quickly, and will not treat an honest mistake in your testing as bad faith.

This authorization covers your research only, and it cannot bind anyone but us — it does not extend to systems operated by our subprocessors or by other third parties. If you are unsure whether something is covered, ask us first at security@totalctrl.app and we will answer.

Rules of engagement

To stay within this policy, please:

  • Use your own data. Create a free workspace and test against that. Do not access, modify, or download data belonging to anyone else.
  • Stop when you have proof. Once you can demonstrate a vulnerability, stop — do not enumerate further records, escalate for its own sake, or maintain access.
  • Tell us immediately if you encounter other people's data, stop testing, and do not save, copy, or share it.
  • Do not degrade the service. Keep automated traffic to a reasonable rate and never test in a way that affects other users' availability.
  • Do not use a vulnerability beyond what is needed to confirm it — no persistence, no pivoting, no backdoors, and remove any test artifacts you leave behind.
  • Give us time to fix it. Please keep the issue confidential until we have shipped a fix, and coordinate publication with us. We will not ask you to stay quiet indefinitely: if we have not fixed an issue within 90 days of confirming it, you are free to publish, and we would appreciate a heads-up first.
  • Do not extort us. Withholding details pending payment, or threatening publication to force one, is not good-faith research and the safe harbor above does not cover it.

Questions about this policy, or about whether something is covered, go to security@totalctrl.app. If you are a customer reporting suspected unauthorized use of your own account, email us at the same address and say so in the subject line — we prioritize those.

← Back to TotalCtrl  ·  Privacy Policy  ·  Terms & Conditions