Introduction
Helply values the work of security researchers who help us protect our customers and services. If you believe you have found a security vulnerability in Helply, please report it to us promptly and follow this policy while conducting your research.
This is a vulnerability disclosure program, not a bug bounty program. We do not promise payment or other compensation for reports.
How to report a vulnerability
Email support@helply.com and begin the subject line with VDP:. Reports without this prefix will not be accepted.
For example: VDP: Authentication bypass in customer portal
Please include, where applicable:
- A description of the vulnerability and its potential impact
- The affected URL, endpoint, feature, or component
- The steps necessary to reproduce the vulnerability
- Any supporting proof of concept, screenshots, or other relevant evidence
- Contact information we can use for follow-up questions
Please provide enough detail for us to reproduce and assess the issue. Protect sensitive information in your report and use encrypted attachments or another secure sharing method when appropriate.
Scope
This Vulnerability Disclosure Program applies only to Helply systems and services. It does not apply to the legacy Groove platform, which is covered by the Groove Legacy Vulnerability Disclosure Program.
Research guidelines
When investigating a potential vulnerability:
- Test only to the extent necessary to confirm the vulnerability.
- Use accounts and data that you own or have explicit permission to use.
- Make a good-faith effort to avoid privacy violations, service disruption, and harm to our customers or systems.
- Do not use social engineering or target our employees, contractors, customers, or vendors.
- Do not conduct denial-of-service or resource-exhaustion testing.
- Do not send spam, perform brute-force attacks, or generate excessive automated traffic.
- Do not perform destructive testing or deploy persistence mechanisms.
- Do not modify or delete data.
- Do not access, copy, download, or retain more customer or sensitive data than is strictly necessary to confirm the vulnerability.
- Do not publicly disclose the vulnerability before we have confirmed remediation or agreed to a disclosure timeline with you.
If you encounter customer data, credentials, personal information, or other sensitive data, stop testing immediately. Do not continue accessing or reviewing the data. Report the exposure promptly using the appropriate email address above, explain what you encountered, and securely delete any locally retained copies after we confirm they are no longer needed for the investigation.
Out of scope
The following activities and findings are outside this program:
- Vulnerabilities in third-party services or systems that we do not operate
- Social engineering, phishing, or physical security testing
- Denial-of-service, distributed denial-of-service, or other availability testing
- Spam, brute force, credential stuffing, or high-volume automated testing
- Destructive testing, persistence, malware, ransomware, or data modification or deletion
- Accessing another person's account or data beyond the minimum necessary to demonstrate an issue
- Reports based only on automated scanner output without a demonstrated security impact
Safe harbor
We consider security research conducted in good faith and in accordance with this policy to be authorized. If your research and disclosure comply with this policy:
- We will not initiate or support legal action against you for the research.
- We will not pursue a claim under the U.S. Computer Fraud and Abuse Act or the anti-circumvention provisions of the U.S. Digital Millennium Copyright Act for actions that were necessary to conduct the research.
- If a third party initiates legal action against you in connection with compliant research, we will take reasonable steps to make it known that your research was conducted in accordance with this policy.
This safe harbor does not apply to actions outside this policy, does not authorize activity that violates applicable law, and cannot bind independent third parties. If you are unsure whether a planned test is permitted, contact us before proceeding.
What happens after you report
We will review reports submitted through the appropriate channel and may contact you for additional information. Please keep vulnerability details confidential while we investigate and address the issue. We ask that you allow us a reasonable opportunity to remediate the vulnerability before any public disclosure.
Reporting a vulnerability in legacy Groove
For vulnerabilities affecting the legacy Groove platform, follow the reporting instructions in the Groove Legacy Vulnerability Disclosure Program.