Skip to main content Skip to bottom nav

Report a Security Vulnerability

People trust 7 Cups with some of the most personal conversations of their lives, so we take the security of our platform seriously. If you believe you have found a security vulnerability, we want to hear from you.

This is a vulnerability disclosure program: we do not pay bounties, but we are grateful for every good-faith report, and we will work with you to understand and fix the issue.

This form is for security vulnerabilities only. For help with your account or other questions, please visit Support & Feedback. If you are in crisis, please see our Crisis Resources.

Scope

In scope: 7cups.com and its subdomains, our API, and the 7 Cups iOS and Android apps.

Out of scope:

  • Third-party services we use (for example payment processors or advertising partners). Please report those to the vendor directly.
  • Denial of service, load testing, or anything that degrades the service for others.
  • Social engineering or phishing of our staff, volunteer listeners, therapists, or members.
  • Physical attacks against our offices or infrastructure.
  • Reports from automated scanners without a demonstrated, exploitable impact.
  • Missing best-practice headers, cookie flags or email (SPF/DKIM/DMARC) settings without a demonstrated impact.

Rules of engagement

  • Test only against accounts you own. Never access, modify, or delete another person’s account, messages, or data.
  • If you encounter anyone else’s personal or health information, stop immediately, do not save or share it, and tell us in your report.
  • Do not contact or message other members, listeners, or therapists as part of your testing, and do not post in the community or forums.
  • Keep automated testing to a low request rate, and stop if you notice any impact on the service.
  • Give us a reasonable amount of time to fix the issue before disclosing it publicly, and coordinate the disclosure with us.

Safe harbor

If you make a good-faith effort to follow this policy, we will consider your research authorized, we will not pursue or support legal action against you for it, and we will work with you to understand and resolve the issue quickly. If you are unsure whether something is allowed, ask us in a report before going further.

Submit a report

Reports are handled through HackerOne. You do not need a HackerOne account to use the form below. Please include the affected URL or app screen, steps to reproduce, and the impact you were able to demonstrate.