Vulnerability disclosure
CramDeck (JMS Sieracki sp. z o.o.) welcomes good-faith reports of security vulnerabilities in our website, APIs, and integrations.
How to report
Email us with enough detail to reproduce the issue. Do not include passwords, session tokens, or personal data belonging to other people.
Security contact: hello@cramdeck.com
- Affected URL, endpoint, or product surface
- Clear steps to reproduce (or a proof-of-concept that does not harm other users)
- Your assessment of impact and any suggested fix
What we do
- We aim to acknowledge receipt within a few business days.
- We triage severity, contain where needed, and track remediation.
- We notify you when a fix is available when you provide a reply address and request an update.
Rules of engagement
- Do not access, modify, or destroy data that is not yours.
- Do not perform denial-of-service, spam, or social-engineering of our staff or users.
- Stay within applicable law; only test systems you are authorized to assess.
- Give us a reasonable time to remediate before public disclosure.
Product support: Support. Privacy rights: Privacy Policy.