Security

Found a security problem? Tell us.

If you believe you have found a vulnerability in the portal or the Windows app, write to security@glacierpointtech.com. This page says what to send, what is covered, the rules we ask you to follow and what you can expect from us.

How to report

Send one email to security@glacierpointtech.com and include:

  • what you found;
  • where you found it: the page or address in the portal, or the version of the app;
  • the steps to reproduce it;
  • how we can reach you, and whether you want to be credited.

The same address and this page are listed in the site's /.well-known/security.txt file.

What is in scope

  • The portal at this site: its pages and the interface they use.
  • The Windows app we distribute from the portal.

What is out of scope

  • Microsoft's own services, such as Microsoft 365, Entra ID and Microsoft Graph. Report those to Microsoft.
  • Any tenant or workspace that is not yours.
  • Services run by other companies, including the ones we use to run ours.

The rules

  • Test only against your own workspace and your own tenant.
  • Do not access, change or delete the data of other customers.
  • No denial of service and no load testing.
  • No social engineering, phishing or physical attacks.
  • No automated scanning that degrades the service.
  • Once you have shown the problem, stop and report it.
  • Give us reasonable time to fix it before you tell others.

What we do

  • We confirm that we received your report within three business days.
  • We tell you what we found and when it is fixed.
  • We credit you if you wish.

We pay no bounties.