Security
Reporting a vulnerability
Report a security issue
We take the security of AppConnect and your connected accounts seriously. If you believe you have found a security vulnerability, please report it to us privately at:
Please do not disclose the issue publicly until we have had a chance to investigate and address it.
Responsible disclosure
We welcome good-faith security research. We will not pursue or support legal action against researchers who:
- Make a good-faith effort to avoid privacy violations, data loss, and service disruption;
- Only access or modify data that belongs to their own test account;
- Give us a reasonable amount of time to respond before any public disclosure; and
- Do not exploit a finding beyond what is necessary to demonstrate it.
We aim to acknowledge reports within 3 business days and to keep you updated as we work toward a fix.
What to include
- A description of the issue and its potential impact;
- Steps to reproduce (proof-of-concept, affected URL, or request/response);
- Any accounts or test data involved (please use a test account where possible).
Scope
AppConnect is operated by Good Samaritan Software LLC. Reports about AppConnect itself, its hosted endpoints, and its handling of connected-account credentials are in scope. Vulnerabilities in third-party services we connect to (such as FreshBooks or Less Annoying CRM) should be reported to those vendors directly.