Reporting a Security Issue or Vulnerability
Overview
If you believe you've found a security vulnerability in AllAccessible — in the widget, the dashboard, our APIs, or one of our plugins — we want to hear from you. This article explains how to report it responsibly, what to include, and what happens after you send it.
We take security seriously and welcome reports from customers, security researchers, and the public. Responsible disclosure helps us protect every site that uses AllAccessible.
Who This Is For
Security researchers who found a potential vulnerability
Customers or developers who noticed unexpected or unsafe behavior
Anyone asking "Do you have a security program or a way to report issues?"
What You'll Learn
How to contact our security team
What information to include in a report
What to expect after you report
What our public security resources cover
Do You Have a Security Program?
Yes. AllAccessible runs an active security program: our platform is regularly scanned for vulnerabilities by independent security tooling, we apply security patches and updates on an ongoing basis, and we maintain a dedicated channel for receiving vulnerability reports.
You can read more about our practices on our public Security page and Trust Center.
A note on "bug bounties": AllAccessible does not currently run a formal, paid bug-bounty program with published payouts or tiers. That does not mean reports aren't valued — they very much are, and they are reviewed and acted on by our security team. We simply don't want to imply a reward structure that isn't in place today.
How to Report a Vulnerability
Send your report by email to our security team:
This is a dedicated address that reaches the people who handle security reports directly.
Please use this address (rather than general support) for anything security-sensitive, so it's routed and handled appropriately. If you're unsure whether something is a security issue, it's fine to send it here and let us assess it.
What to Include in Your Report
The more detail you provide, the faster we can verify and address the issue. Where possible, include:
A clear description of the vulnerability and its potential impact
Steps to reproduce it — as specific as you can make them
The affected area — for example the widget, the dashboard (app.allaccessible.org), a specific API endpoint, or a plugin (WordPress, Shopify, etc.)
Proof of concept — a request, script, screenshot, or short recording, if you have one
Environment details — browser, operating system, plugin version, or site URL where relevant
Your contact information so we can follow up with questions or updates
📷 Example of a well-structured vulnerability report email
Responsible Disclosure — What We Ask
To keep everyone's data safe while an issue is being investigated, we ask that you:
Give us a reasonable opportunity to investigate and fix the issue before disclosing it publicly or to third parties.
Avoid privacy violations and data destruction. Don't access, modify, or delete data that isn't yours, and don't run tests that could degrade service for other customers (for example, denial-of-service testing).
Only interact with accounts you own or have explicit permission to test.
Act in good faith. Reports made in good faith to help us improve security are welcome.
What Happens After You Report
Here's the general path a report follows once it reaches us:
Acknowledgement — Our security team receives and reviews your report.
Assessment — We work to reproduce and verify the issue, and to understand its severity and scope.
Remediation — Confirmed issues are prioritized and fixed, with security patches applied as part of our ongoing update process.
Follow-up — We may contact you for clarification, and we can confirm when an issue has been resolved.
We're a focused team and handle each report individually. Because timelines depend on the complexity and severity of the issue, we don't publish a fixed response-time or resolution guarantee. We do commit to reviewing every good-faith report and acting on valid findings.
Frequently Asked Questions
Q: Is there a reward or payout for reporting a vulnerability?
A: We don't currently offer a formal paid bug-bounty program. Reports are still genuinely valued and are reviewed and acted on by our security team.
Q: Should I report through general support instead?
A: For anything security-sensitive, please use [email protected] so it reaches the right people directly. For non-security questions, general support ([email protected]) is the right channel.
Q: Can I disclose the issue publicly?
A: We ask that you give us a reasonable chance to investigate and fix the issue before any public disclosure, so that customers using AllAccessible aren't put at risk.
Q: I'm a customer, not a researcher — I just noticed something odd. Should I still report it?
A: Yes, please do. If something looks like it could be a security or privacy issue, send it to [email protected] and we'll assess it.
Q: Where can I read about your overall security practices?
A: See our public Security page and Trust Center, which cover our security scanning, updates, and compliance documentation.
Related Articles
Need Help?
For security reports and vulnerability disclosures, email [email protected]. For general, non-security support, contact [email protected].
Last Updated: July 2026
Article Category: Troubleshooting
Related Resources: Security, Trust Center
