Vulnerability disclosure
- Effective date
- August 17, 2026
- Applies to
- Vulnerability reports about TakePublic
- Contact
- hello@takepublic.com
- Version
- Current
Security research helps TakePublic protect customer filing data, material non-public information, pre-release financials, and insider personal information.
How to report
Email security@takepublic.com. Do not open a public GitHub issue. Keep the report and supporting material confidential while we investigate.
Include the affected host, endpoint, or feature; the vulnerability type and expected impact; clear reproduction steps or a proof of concept; the date, time, and time zone of testing; relevant request and response details with secrets and personal data removed; whether you accessed or changed customer data; and your preferred contact information.
Do not include customer content, credentials, access tokens, or other sensitive data unless we ask for a secure transfer.
Scope
Reports may cover:
- the customer application at app.takepublic.com;
- the TakePublic API;
- the takepublic.com marketing site and free scanner;
- authentication, authorization, filing integrity, or data isolation issues in those systems.
Out of scope and testing limits
Third-party products and SEC EDGAR are outside our control. Report an issue in a third-party product to that provider unless the issue results from how TakePublic uses or configures it.
Do not use denial-of-service testing, social engineering, physical intrusion, spam, destructive testing, or automated scanning that degrades the Service. Use only the minimum access needed to demonstrate the issue. Stop testing and notify us immediately if you encounter customer data.
Safe harbor
TakePublic will not pursue legal action against good-faith security research that follows this policy, avoids privacy violations and service disruption, uses only the minimum access needed to demonstrate the issue, and gives us a reasonable opportunity to investigate before public disclosure. This safe harbor does not authorize activity prohibited by applicable law or by third parties.
What to expect
We will acknowledge a complete report within 2 business days and provide an initial status update within 7 calendar days. We will investigate in good faith, share material progress, and coordinate disclosure timing when a confirmed issue affects customers. Resolution time depends on severity, complexity, and third-party dependencies.
TakePublic does not currently operate a paid bug bounty program. We welcome responsible reports and may credit researchers when requested and appropriate.
Questions? Contact hello@takepublic.com.