TextAdmin

Security policy

This product handles real people's phone numbers, street addresses and SMS conversations. If you have found a way to reach any of that — or to send SMS as a business using it — we want to hear from you before anyone else does.


Reporting a vulnerability

security@contextsolutions.com

Please include enough to reproduce it: the endpoint, app version or commit, the request or steps, and what you were able to observe or change. A proof-of-concept is welcome and never required — a clear description of the flaw is worth more than a working exploit.

Safe harbour

We will not pursue legal action, or ask anyone else to, over good-faith research that follows this policy: testing only against your own installation or infrastructure you own, avoiding access to other people's data, and giving us a reasonable chance to fix the issue before publishing.

If you access someone else's data by accident — which is possible in exactly the class of bug we care most about — stop, tell us, and delete what you retrieved. That is not a rule violation; not telling us would be.

There is no bug bounty. We would rather say so plainly than leave it ambiguous.

Scope

In scope

Out of scope, deliberately, because they are unauthenticated by design and documented as such:

Design commitments you can hold us to

These are product promises, so a way around any of them is a vulnerability report even if nothing obviously "leaks":