<img height="1" width="1" style="display:none" src="https://www.facebook.com/tr?id=292010438930434&amp;ev=PageView&amp;noscript=1">

Vulnerability Disclosure Policy

Reporting Security Issues Responsibly at Confido Legal

Protecting our customers and their data is a priority at Confido Legal. If you believe you have identified a security vulnerability in a Confido system, we encourage you to report it so we can investigate and address it promptly.

Key aspects of our policy:

 

Reporting a vulnerability

Submit your report through our secure report form or email security@confidolegal.com.

Please include the affected asset, a description of the issue and its potential impact, minimal steps to reproduce it, the date and time of testing, and any redacted supporting evidence. Relevant test-account, source-IP, request, or correlation identifiers can help us locate your activity.

Do not send live credentials, complete access tokens, private keys, payment information, personal data, client information, or other sensitive data by ordinary email. If unredacted information is necessary, ask us for a secure method before sending it.

You may report under a pseudonym or anonymously, although we cannot follow up without a contact method.

Policy Scope

This policy applies to the following Confido-owned or -operated services:

  • confidolegal.com and Confido-controlled subdomains, including app.confidolegal.com, docs.confidolegal.com, and app.sandbox.confidolegal.com
  • app.gravity-legal.com, api.gravity-legal.com, and api.sandbox.gravity-legal.com

Use the sandbox wherever possible. Testing in production must be limited to the minimum non-destructive activity needed to confirm a vulnerability.

Third-party systems—including hosting providers, financial institutions, card networks, identity providers, payment processors, communications providers, and analytics providers—are not in scope, even when integrated with a Confido service. You may report an issue observed through Confido, but do not test a third party directly.

Reports of best-practice gaps without a demonstrable security impact may be closed as informational. Examples include unvalidated scanner output, version banners, missing headers, low-impact clickjacking, self-XSS, and rate-limit observations without meaningful impact.

ChatGPT Image Sep 8, 2026, 04_40_30 PM

Research guidelines

When testing, please:

  • Use only accounts you own and synthetic test data.
  • Avoid privacy violations, service disruption, data destruction, and harm to Confido, our customers, or third parties.
  • Stop testing and notify us immediately if you encounter nonpublic data, credentials, access beyond your own account, administrator control, or the ability to affect a payment.
  • Do not copy, download, retain, or disclose sensitive data; use discovered credentials; establish persistence; pivot to another system or tenant; alter data; or change another user’s settings.
  • Do not initiate, simulate, reverse, redirect, refund, or otherwise affect a real payment or funds transfer.
  • Do not conduct denial-of-service or resource-exhaustion testing, high-volume automated scanning, malware deployment, credential stuffing, brute force, phishing, social engineering, physical attacks, spam, or testing that contacts our customers, staff, or vendors.
  • Do not engage in extortion, and comply with applicable law.

If you are unsure whether a target or technique is allowed, contact us before proceeding.

ChatGPT Image Sep 8, 2026, 04_41_56 PM

 Disclosure and response

 

Please keep vulnerability details confidential while we investigate. Unless we agree otherwise in writing, you may publicly disclose the issue after we confirm remediation or 90 calendar days after your initial report, whichever comes first. Give us at least seven calendar days’ written notice before disclosure, and never publish credentials, personal data, client information, payment data, or other information that could harm a third party.

We aim to acknowledge reports within two business days, provide an initial assessment or request more information within five business days, keep you reasonably informed, and notify you when the issue is resolved. These are good-faith targets, not guarantees; remediation time depends on severity and complexity.

 

 

ChatGPT Image Sep 8, 2026, 04_45_51 PM

 Safe harbor

 

If you make a good-faith effort to follow this policy, Confido will consider your research on in-scope systems to be authorized. We will not initiate or support legal action against you for accidental, good-faith violations. We also consider policy-compliant research authorized under applicable computer-access and anti-circumvention laws and waive, on a limited basis, provisions in our terms that would prohibit the research permitted here.

If a third party initiates legal action concerning policy-compliant research, we will make this authorization known. This safe harbor applies only to claims Confido controls; it does not bind third parties, authorize access to third-party systems or data, excuse violations of law, or cover conduct outside this policy.

Thank you for helping us keep Confido and our customers secure.