1. Our commitment
Salesjet (operated by Banzai House LLC, a Veracor Group company) values the security research community. We are committed to working with researchers who report vulnerabilities in good faith. This policy explains how to report a vulnerability, what is in and out of scope, how we will respond, and the safe-harbor protections we extend to researchers who follow it.
2. Safe harbor
If you make a good-faith effort to comply with this policy during your security research, we will: (a) consider your research authorized and not pursue or support any civil action or criminal complaint against you for accidental, good-faith violations of this policy; (b) consider your research authorized under the U.S. Computer Fraud and Abuse Act (CFAA), the Digital Millennium Copyright Act (DMCA) anti-circumvention provisions, and applicable state computer-crime statutes; (c) waive any restriction in our Terms of Service or Acceptable Use Policy that would prohibit your participation, solely for the purpose of this policy; and (d) work with you to understand and resolve the issue quickly. If a third party initiates legal action against you for activities conducted in accordance with this policy, we will make it known that your actions were authorized.
3. Scope (in scope)
- atomauthority.com and its subdomains (including app.atomauthority.com, auth.atomauthority.com, api.atomauthority.com)
- The ATOM Content Intelligence Platform and the Salesjet web application
- Public API endpoints under /api/public/*
- First-party JavaScript and configuration we serve from the above hosts
4. Out of scope
- Third-party services, sub-processors, and SaaS dashboards we use (Cloudflare, Supabase, Stripe, OpenAI, Google, Resend, PostHog) — report to the vendor directly
- Physical security, social engineering of our employees or contractors, and attacks against our offices or staff
- Denial-of-service, volumetric, or resource-exhaustion testing against production
- Automated scanning that generates significant traffic or noise without prior coordination
- Findings limited to missing security headers without a demonstrated impact (e.g., CSP, HSTS, X-Frame-Options)
- Reports from automated tools or scans without a working proof of concept
- Self-XSS, clickjacking on pages with no sensitive actions, CSRF on logout or other low-risk endpoints
- Email spoofing issues caused by missing SPF, DKIM, or DMARC on non-mail-sending domains
- Vulnerabilities in unsupported browsers or end-of-life software
- Recently disclosed (less than 30 days) vulnerabilities in upstream dependencies, where a patched version is not yet generally available
- Issues that require physical access to a victim's unlocked device
5. Rules of engagement
- Only test against accounts you own or have explicit written permission to test. Do not access, modify, or delete other users' data.
- Use only the minimum interaction necessary to demonstrate a vulnerability. Stop and report as soon as impact is confirmed.
- Do not exfiltrate, retain, or disclose customer data. If you inadvertently access it, stop, do not store copies, and notify us immediately.
- Do not perform destructive testing, run automated scanners at high volume, or attempt denial-of-service.
- Do not test the physical security of our offices, attempt social engineering of our employees or vendors, or compromise the accounts of others.
- Comply with all applicable laws, including the laws of the jurisdiction where you reside and from which you test.
- Keep vulnerability details confidential until we have had a reasonable opportunity to remediate. See coordinated disclosure below.
6. How to report
Send your report to security@salesjet.pro. Where possible, encrypt sensitive content using our PGP key (available on request from the same address). Our machine-readable contact is published at /.well-known/security.txt in accordance with RFC 9116. A high-quality report includes: the affected asset (URL, endpoint, parameter), a clear technical description, step-by-step reproduction instructions, a working proof of concept, the impact you believe the issue has, and your suggested remediation if any. If you are reporting under a handle or organization, tell us how you would like to be credited.
7. Our response timeline
- Acknowledgment: within 3 business days of receipt
- Triage and severity assessment: within 10 business days
- Status updates: at least every 14 calendar days while the issue is open
- Target remediation windows: Critical within 7 calendar days, High within 30 calendar days, Medium within 90 calendar days, Low at our discretion
- Public disclosure: coordinated with you after remediation is deployed and customers have had a reasonable opportunity to apply any necessary actions
8. Coordinated disclosure
We follow a 90-day coordinated disclosure model. We ask that you do not publicly disclose details of a reported vulnerability until we have remediated it and we have agreed on a disclosure date with you. If we have not remediated within 90 days, we will work with you in good faith on an extension or, if no extension is possible, on coordinated public disclosure timing.
9. Recognition
We do not currently operate a paid bug bounty. We will, with your permission, publicly thank researchers who submit valid reports on our Trust page and in security advisories. We may offer Salesjet credits or merchandise at our discretion for impactful findings.
10. No-bounty disclaimer
Submission of a report under this policy does not entitle you to monetary compensation. Any reward we offer is at our sole discretion and may be subject to applicable tax reporting in your jurisdiction.
11. Eligibility
You are not eligible for safe harbor or recognition if you (a) are a current or former employee, contractor, or vendor of Salesjet within the past 12 months and the finding relates to systems you had authorized access to; (b) reside in a jurisdiction subject to U.S. sanctions or comprehensive embargoes; (c) are on a U.S. or EU denied-parties list; or (d) are under 14 years of age.
12. Privacy of researcher information
Personal information you provide in a report is processed under our Privacy Policy. We retain reports for the period reasonably necessary to validate, remediate, and document the issue, and for a reasonable additional period for audit and legal purposes.
13. Changes to this policy
We may update this policy from time to time. The current version, with effective date, is always posted at this URL. Material changes will be summarized at the top of the page for at least 30 days.
14. Contact
Security reports: security@salesjet.pro. Legal questions about this policy: legal@salesjet.pro. Postal address available on request.
