Responsible Disclosure
Responsible disclosure
SmartQuotes welcomes responsible reports of security issues from researchers, users, and partners. This policy is not a bug bounty program and does not authorize testing that degrades service, accesses data, or disrupts users.
Security contact
Report suspected security issues to security@smartquotespartners.com. Please include a clear description, the affected URL or endpoint, reproduction steps, the impact, and your contact information.
Our machine-readable policy is published at /.well-known/security.txt.
Safe-harbor boundaries
- Do not access, modify, delete, or exfiltrate data that does not belong to you.
- Do not perform denial-of-service testing or high-volume automated scanning against production systems.
- Do not attempt social engineering, phishing, physical attacks, or attacks against third-party providers.
- Give SmartQuotes a reasonable opportunity to investigate and remediate before public disclosure.
For enterprise review
Highlights for review
- security@smartquotespartners.com active and receiving
- security.txt available
- Non-destructive reporting requested
- Enterprise security inquiries routed to the same contact
SmartQuotes is building its security and operational practices in alignment with SOC 2 Trust Services Criteria. SmartQuotes has not completed a SOC 2 Type I or Type II audit, and nothing on these pages is a certification, attestation, or audit report. Status labels reflect current readiness, not completed controls.