Vulnerability Disclosure Policy
Last updated September 28, 2026Effective September 28, 2026
Circo, Inc. ("Accountable", "we" or "us") welcomes good-faith reports from security researchers. This Policy explains which systems may be tested, how to test them safely, and how to report a potential vulnerability. Accountable does not currently offer a paid bug bounty.
1. Safe harbor
If you make a good-faith effort to follow this Policy, Accountable will treat your research as authorized under the Computer Fraud and Abuse Act, comparable state computer-crime laws, and the anti-circumvention provisions of the Digital Millennium Copyright Act. We will not pursue or support legal action against you for that research, and we waive claims under our Terms of Service and Acceptable Use Policy to the extent they arise from activity this Policy permits.
This safe harbor does not cover unlawful conduct, bad-faith activity, or testing outside this Policy. We cannot authorize testing of third-party systems, accounts or data, and third parties are not bound by this Policy. If you are unsure whether proposed testing is permitted, email security@accountable.im before you start.
2. Scope
This Policy applies to the following assets, but only to the extent they are owned, operated or controlled by Accountable:
- accountable.im and its subdomains, and the Accountable web application;
- the Accountable public API, MCP server and OAuth authorization server, and our command-line tools; and
- authentication, authorization, account recovery, roles and permissions, approval rules, and the separation between companies and workspaces in those assets.
A third-party platform, cloud service, financial institution, AI provider, customer environment or integration (for example Cloudflare, Stripe, Plaid, Google or Slack) is not in scope merely because Accountable uses or links to it. Vulnerabilities in Accountable-controlled code or configuration remain in scope, but do not test the third party's infrastructure without its separate authorization.
3. Research guidelines
When conducting research:
- Use only accounts you own or test accounts you create, and use synthetic data. Create your own companies for testing; never use a real company's books.
- Use the least invasive method available, and stop once you have confirmed the vulnerability.
- Keep automated testing low-volume, targeted and non-disruptive, and independently verify scanner or AI-tool output.
- If you encounter data that is not yours, stop immediately, do not copy or retain it, and report the exposure with sensitive details redacted.
- Protect all information obtained through your research, and securely delete it when it is no longer needed for reporting.
The following activities are not authorized:
- denial-of-service, load, stress, resource-exhaustion or rate-limit testing;
- credential stuffing, password spraying, brute force, account-lockout testing, or use of credentials, codes or tokens not issued to you;
- social engineering, phishing, impersonation, physical intrusion, malware, spam, mass account creation, persistence, privilege escalation beyond a minimal proof, or lateral movement;
- accessing, changing, downloading, transmitting or retaining another person's data beyond the minimum observation needed to report the issue;
- creating or altering real accounting records, invoices, W-9 requests, bank connections, emails to third parties, or other workflows that affect real companies or people;
- testing third-party systems, or contacting affected customers, users, vendors or financial institutions; or
- demanding payment or another benefit in exchange for withholding or disclosing a finding.
4. Reporting a vulnerability
Email your report to security@accountable.im. Do not include unredacted customer data, credentials, authentication tokens, malware, destructive code or weaponized payloads. If sensitive supporting material is necessary, say so in your first email and we will arrange a secure way to receive it.
A useful report includes:
- the affected product, URL, endpoint, tool or feature;
- a clear description of the issue, its security impact and a realistic attack scenario;
- concise, reproducible steps and a safe proof of concept;
- relevant screenshots, logs, requests or responses, with sensitive information redacted; and
- whether you encountered or affected any real data, accounts or services.
Please send one vulnerability per report, unless several issues are needed to demonstrate a single attack chain.
5. Reports we may close as informational
We may close a report that is out of scope, not reproducible, duplicative, or without meaningful security impact. Examples include:
- raw or unverified scanner or AI-tool output;
- missing security headers, cookie attributes, email-authentication records, TLS configuration or other hardening recommendations without a working exploit;
- self-XSS, low-impact clickjacking or CSRF, open redirects, enumeration or verbose errors without material impact;
- AI-output quality issues, including inaccurate answers or prompt injection, that do not produce unauthorized access, cross-company exposure, an approval bypass or an unauthorized change to the books; and
- product feedback, account-support or privacy requests, or vulnerabilities solely in a third-party product.
6. What you can expect
We aim to acknowledge your report within three (3) business days, to tell you within ten (10) business days whether we have confirmed it and how we rate its severity, and to keep you informed of material progress until it is resolved. We prioritize issues by severity, exploitability, the systems and users affected, and risk to customer data, credentials, company separation or the integrity of the books. Remediation timing depends on the nature and complexity of the issue.
7. Coordinated disclosure and recognition
Do not publicly disclose a vulnerability, exploit details, proof-of-concept code, screenshots, data or related information until Accountable has remediated the issue or agreed in writing, and in any case give us at least ninety (90) days from your report. Any public disclosure must not include personal information, financial information, credentials, customer data or other sensitive material.
At your request, we may recognize you for a valid report. We will not identify you publicly without your permission. No payment, reimbursement, employment or other compensation is offered or owed for reports under this Policy.
8. Questions and updates
Questions about this Policy or whether an asset is in scope may be sent to security@accountable.im. Our security.txt lists the same contact. Accountable may update this Policy from time to time; every earlier version stays readable from the version history below, and good-faith research conducted under the version in effect when it began remains covered by that version's safe harbor.
Version history
- September 28, 2026Effective September 28, 2026First published version.
Questions about this document: legal@accountable.im.