We welcome reports from independent researchers who help keep AcquireLens users safe. Please follow the guidelines below when investigating and reporting a vulnerability.
In scope
- The AcquireLens web application and its public API endpoints.
- Authentication, authorization, and tenant-isolation flaws.
- Server-side request forgery, injection, and remote code execution.
- Sensitive data exposure and misconfigured storage.
Out of scope
- Denial-of-service, volumetric, or rate-limit stress testing.
- Social engineering, phishing, or physical attacks against staff.
- Third-party services we integrate with — report those to the vendor directly.
- Reports based solely on automated scanner output with no proven impact.
Rules of engagement
- Use only accounts you own or have explicit permission to test.
- Do not access, modify, or delete other users' data.
- Stop as soon as you demonstrate impact and report immediately.
- Do not publicly disclose the issue until we have released a fix.
Safe harbor
If you make a good-faith effort to comply with this policy, we will not pursue legal action against you, and we will work with you to understand and resolve the issue quickly.
How to report
- Email: support@acquirelens.ai
- Include steps to reproduce, impact, and any proof-of-concept output.
- We aim to acknowledge reports within 2 business days.