The security of your data and account is important to us. If you discover or suspect a security incident involving Stally, please report it as soon as possible.
A security incident may include:
Unauthorized access to your account or organization.
Unexpected changes to users, permissions, domains, or settings.
Exposure of personal, confidential, or customer data.
A compromised API key, access token, password, or authentication session.
Suspicious activity that appears to originate from Stally.
A vulnerability that may affect the confidentiality, integrity, or availability of the service.
Any other behavior that may indicate a security problem.
Immediate actions
If you believe credentials or access tokens have been compromised:
Revoke or rotate the affected credentials immediately, if possible.
Review and remove unrecognized users or access.
Preserve relevant logs, timestamps, request IDs, emails, and screenshots.
Contact us using one of the reporting methods below.
Do not delete evidence that may help us investigate the incident.
How to report an incident
You can report a security incident through either of these channels:
Email: [email protected]
Intercom: Start a conversation and select Report a security incident.
For urgent incidents involving active unauthorized access or data exposure, include URGENT SECURITY INCIDENT in the subject or first line of your message.
Do not report security incidents through social media, public forums, public issue trackers, or other public channels.
Information to include
Please provide as much of the following information as possible:
Your name and contact details.
Your organization or account name.
The affected account, domain, user, or resource.
A description of what happened.
When you first noticed the issue, including your time zone.
Whether the incident is still happening.
The potential impact or data involved.
Relevant URLs, request IDs, IP addresses, timestamps, logs, or screenshots.
Actions you have already taken.
The best way and time to contact you.
Please do not send passwords, complete API keys, access tokens, private keys, authentication cookies, or unnecessary personal data. If we need sensitive evidence, we will arrange an appropriate secure way to provide it.
What happens after you report an incident
After receiving your report, our team will:
Confirm that we received it.
Review the available information and assess the severity.
Contact you if additional information is required.
Investigate and take appropriate containment or remediation actions.
Provide relevant updates while the investigation is active.
Notify you when the incident has been resolved or when no further action is required.
The time required to investigate depends on the nature and complexity of the incident. Critical incidents involving active unauthorized access or confirmed data exposure are prioritized.
Confidentiality
We treat security incident reports as confidential and share them internally only with the people needed to investigate and respond.
If an incident affects personal data, we will handle it according to our contractual, privacy, and legal obligations.
Security vulnerability reports
If you are a security researcher reporting a vulnerability rather than an incident affecting your customer account, contact [email protected] and review our vulnerability disclosure guidance at security policy URL.
Please do not test vulnerabilities against customer accounts or data without explicit authorization.
Questions
For general security questions that do not involve an active or suspected incident, contact us through Intercom or email [email protected].
