Security
If you find a security vulnerability in GrowthSync, please report it to us directly. We will investigate all legitimate reports and work to resolve issues quickly.
Scope
In scope: app.growthsync.com, our API, authentication flows, data handling.
Out of scope: Third-party integrations (Instagram, TikTok, Stripe), our marketing site, denial of service, social engineering.
Ground rules
Do not access or modify other users’ data.
Do not run automated scanners against production.
Give us 90 days to fix before public disclosure.
Test against your own account only.
How to report
Email engineering@growthsync.com with a description of the vulnerability, steps to reproduce, and any supporting screenshots or proof-of-concept code.
We will acknowledge your report within 3 business days.
Severity levels
Critical — auth bypass, mass data exposure.
High — privilege escalation, data leak.
Medium / low — logic flaws, best-practice gaps.
Last updated: July 2026.
