Responsible Disclosure

Responsible disclosure

SmartQuotes welcomes responsible reports of security issues from researchers, users, and partners. This policy is not a bug bounty program and does not authorize testing that degrades service, accesses data, or disrupts users.

Security contact

Report suspected security issues to security@smartquotespartners.com. Please include a clear description, the affected URL or endpoint, reproduction steps, the impact, and your contact information.

Our machine-readable policy is published at /.well-known/security.txt.

Safe-harbor boundaries

  • Do not access, modify, delete, or exfiltrate data that does not belong to you.
  • Do not perform denial-of-service testing or high-volume automated scanning against production systems.
  • Do not attempt social engineering, phishing, physical attacks, or attacks against third-party providers.
  • Give SmartQuotes a reasonable opportunity to investigate and remediate before public disclosure.

For enterprise review

Highlights for review

  • security@smartquotespartners.com active and receiving
  • security.txt available
  • Non-destructive reporting requested
  • Enterprise security inquiries routed to the same contact
SmartQuotes is building its security and operational practices in alignment with SOC 2 Trust Services Criteria. SmartQuotes has not completed a SOC 2 Type I or Type II audit, and nothing on these pages is a certification, attestation, or audit report. Status labels reflect current readiness, not completed controls.