- 01
Report
Email security@tryadvocate.com with a summary, reproduction steps, your environment and any proof of concept.
- 02
Triage
We confirm receipt, reproduce the issue and assess its severity and real-world impact.
- 03
Remediate
We fix the issue and keep you informed along the way. We may come back with questions.
- 04
Disclose
Once resolved, we update affected customers where warranted and settle any reward.
How to report
Send your report to security@tryadvocate.com. To help us reproduce and assess it quickly, include:
- What the issue is and what someone could do with it.
- Step-by-step instructions to reproduce it.
- The environment you tested from: URLs, account type, browser or client, and any relevant configuration.
- Proof-of-concept code or a recording, if you have one.
We will acknowledge your report, investigate, and keep you informed as we work. We may ask for more detail along the way. Once the issue is resolved we let affected customers know where that is warranted.
Please include only the customer data strictly necessary to demonstrate the issue, and never send us data that belongs to other customers.
What we prioritize
We care most about issues that cross a trust boundary. These get the fastest response and the highest rewards:
- Reading, changing or deleting data that belongs to another customer or workspace.
- Weaknesses in authentication or session handling: bypasses, account takeover, or leaked credentials and tokens.
- Remote code execution and server-side injection, including SQL or NoSQL injection and server-side request forgery.
- Authorization flaws in the public API or in Advocate-built integrations that return data beyond the caller’s permissions.
- Flaws in document ingestion or AI processing that expose one customer’s documents or extracted data to another.
Lower priority, and usually lower rewards:
- Client-side issues such as cross-site scripting or request forgery without a demonstrated, meaningful impact.
- Information disclosure that does not reveal sensitive data.
- Moving between roles inside a workspace you already have access to.
Scope
The following are in scope:
- www.advocate.appThis website
- app.tryadvocate.comThe Advocate application
- api-v2.tryadvocate.comThe public API
- Integrations and clients published by Advocate
Anything not listed above is out of scope. That includes our Trust Center, help center, API documentation and status page, which run on third-party platforms; please report issues in those to the platform provider. Our subprocessors' own infrastructure is likewise outside this program.
Out of scope
The following kinds of testing are not permitted, and reports arising from them are not eligible:
- Findings from automated scanners that have not been verified by hand.
- Social engineering of Advocate staff, customers or vendors, including phishing.
- Denial of service, resource exhaustion, or anything that degrades the service for others.
- Attacks that require physical access to a device or facility.
- Theoretical issues without a working demonstration of impact.
- Attacks that require a privileged network position, such as man-in-the-middle.
- Clickjacking on pages that carry no sensitive actions.
- Actions a workspace administrator or owner can take against their own workspace.
- Circumventing plan limits or billing restrictions.
Some observations are useful hardening advice but are not treated as vulnerabilities unless you can show real impact:
- The presence or configuration of HTTP security headers, TLS settings, or DNS and email authentication records.
- Software version banners and verbose error messages that reveal no sensitive data.
- Rate limiting on endpoints that do not handle authentication or sensitive actions.
- Best-practice recommendations without a demonstrated attack.
Rules of engagement
To keep our customers safe, and to stay covered by the safe harbor below, we ask that you:
- Test only with accounts you own, or with the explicit permission of the account owner.
- Do not access, copy, modify or delete data that is not yours. If you come across another customer’s data, stop and report it to us immediately.
- Do not degrade, disrupt or overload the service.
- If you gain access to a system, do not go further. Stop, document what you found, and report it.
- Give us a reasonable amount of time to fix the issue before sharing it publicly, and agree the timing of any disclosure with us first.
- Use what you find only to report it to us. Extortion, threats of disclosure or selling the finding put you outside this program.
Rewards
We pay rewards for qualifying reports. Amounts are decided case by case, guided by the CVSS 4.0 base score of the issue, generally 4.0 or higher to qualify, together with the sensitivity of the affected component and the realistic impact on our customers. We reward the first complete report of a given issue. Duplicates, findings outside scope, and issues without demonstrable impact are not eligible.
Safe harbor
Security research carried out in good faith and in keeping with this policy is authorized. We will not initiate or support legal action against you for it. If a third party brings a claim against you for activity we consider consistent with this policy, we will take steps to make it known that your research was authorized.
If you are not sure whether something you plan to do is covered, ask us first at security@tryadvocate.com and we will tell you.
Contact
Email security@tryadvocate.com. For everything else about our security program, see the Security overview and the Trust Center.