Toppp handles customer sales conversations, so we take reports about our systems seriously. If you believe you have found a vulnerability, please tell us before you tell anyone else.
In scope:
toppp.aiand everything served under it- The Toppp web application and its APIs
- Any Toppp library or embeddable component we have published, in this organisation or on npm
Out of scope:
- Findings that require physical access to a user's device, or a compromised browser
- Reports produced only by an automated scanner, with no demonstrated impact
- Missing hardening headers or best-practice suggestions with no exploitable consequence
- Social engineering of Toppp staff or customers
- Denial of service, load testing, or any test that degrades service for real users
Email business@toppp.ai with SECURITY in the subject line.
Please include:
- The affected domain, URL or endpoint
- What the issue is, and what an attacker could do with it
- Reproduction steps, or a minimal proof of concept
- Anything that helps us reproduce it — request/response captures, screenshots, timestamps
If you need to send something sensitive, say so in your first email and we will arrange an encrypted channel.
Please do not open a public GitHub issue or disclose the finding publicly before we have had a chance to fix it.
We answer every report. We do not publish a fixed response window, but this is the sequence you can expect:
- We confirm we have received it
- We tell you whether we can reproduce it, and what we intend to do
- We keep you updated while we work on a fix, and let you know when it ships
- With your permission, we credit you once the fix is live
We will not pursue legal action against you for security research carried out in good faith under this policy, provided you:
- Stay within the scope above
- Do not access, modify or retain data that is not your own — if you encounter customer data, stop and tell us immediately
- Do not degrade or disrupt the service for other users
- Give us reasonable time to remediate before any public disclosure
We do not currently run a paid bug bounty programme.