This Responsible Disclosure policy explains how to report security issues to SalesSign safely; we publish a security.txt file pointing here. SalesSign welcomes reports from security researchers. This policy explains how to report a vulnerability to us, what is in scope, and the safe-harbour protection we offer for good-faith research.
Last updated: 3 June 2026
The security of SalesSign and the data our customers entrust to us matters to us. We believe that working openly with the security research community makes our products safer. We are committed to:
SalesSign is a Salesforce-native proposal and eSignature platform. Customer documents and CRM data live inside the customer’s own Salesforce org; our marketing website and our web application are hosted on separate infrastructure. SalesSign is currently undergoing Salesforce’s AppExchange Security Review.
This policy applies to the SalesSign systems we own and operate. Before testing, please confirm a target is in scope.
The following classes of issue are generally of interest to us: authentication and authorisation flaws, injection, server-side request forgery, insecure direct object references, remote code execution, exposure of secrets or customer data, and significant business-logic flaws.
The following are out of scope. Please do not test against them, and reports about them will usually be closed without action:
To keep research safe for everyone, we ask that you:
We consider security research and vulnerability disclosure conducted in good faith and in accordance with this policy to be authorised activity. Where you act in good faith and stay within this policy:
This safe harbour does not extend to activity that is unlawful, that falls outside the scope above, that accesses or damages data belonging to others, or that otherwise breaches this policy. If legal action is initiated by a third party against you for activity conducted in line with this policy, and you have complied with it, we will take reasonable steps to make it known that your actions were authorised. If you are ever unsure whether specific testing is permitted, contact us first and ask.
Please send your report to our security team at admin@salessign.io. We prefer reports in English.
To help us triage and reproduce the issue quickly, please include:
Please do not include real customer data in your report. If your testing inadvertently exposed personal or customer data, tell us in the report and do not retain, copy, or share it.
/.well-known/security.txt file should be published on the SalesSign website pointing to the canonical URL of this page (Policy:) and to the security contact above (Contact:), so researchers can find the right channel quickly. Keep the Expires field current.These are the targets we aim to meet for reports that follow this policy. They are goals, not contractual commitments, and may vary with severity and complexity.
| Stage | Target |
|---|---|
| Acknowledge receipt of your report | Within 5 business days |
| Initial triage and severity assessment | Within 10 business days |
| Status update on validated reports | at least every 10 business days |
| Remediation target for confirmed issues | Prioritised by severity; we will share an indicative timeline once triage is complete |
We will keep you informed of our progress and let you know when the issue has been resolved. SalesSign does not currently operate a paid bug-bounty programme; we are, however, happy to acknowledge researchers who report valid issues — see below.
Please give us a reasonable opportunity to investigate and fix an issue before disclosing it publicly. We ask that you do not publish, share, or otherwise disclose details of a vulnerability until we have confirmed it has been resolved and have agreed a disclosure timing with you. We will work with you in good faith on a coordinated disclosure timeline and are glad to credit researchers who report valid issues, with your consent.
If you would like to be credited for a valid report, let us know in your submission and we will acknowledge your contribution once the issue is resolved, subject to your agreement on what is published.
We may update this policy from time to time. The version in force is the one published on this page, with the effective date shown above. Reports are handled under the policy in force at the time of submission.
Research conducted in line with this policy is authorised. We will not pursue legal action against good-faith reporters who stay within scope.
One contact inbox, a defined list of what to include, and a request to keep findings confidential until a fix is confirmed.
We aim to acknowledge, triage, and keep you updated on a published schedule, and we coordinate disclosure with you once an issue is fixed.
If anything here is unclear, or you are unsure whether specific testing is permitted, please contact our security team at admin@salessign.io before you begin. For broader information about how we protect customer data, see our Security & Trust page or browse all legal & trust documents.