Report a Vulnerability
1. Why we want to hear from you
Snapline holds photographs of people's homes and workplaces, the addresses those photographs were taken at, and the reports contractors send to their customers. If you have found a way to reach data or functionality you should not be able to reach, we would much rather hear it from you than from a customer.
2. How to report
Email security@voice2jobs.com. Please include:
- What the issue is, and what someone could do with it.
- Clear steps to reproduce. A short recording, or a request and response pair, is ideal.
- The endpoint, screen or share-link URL involved, and roughly when you found it.
- Which account you used. If you needed a test account, say so and we will confirm it was yours.
Please report in English where you can, and please do not post publicly or contact individual staff before we have replied.
3. What we commit to
- We acknowledge reports within 3 business days.
- We give you an initial assessment — whether it is in scope, and how severe we think it is — within 10 business days.
- We keep you updated while we work on a fix, and we tell you when it ships.
- We will credit you if you want to be credited, and not if you don't.
4. Safe harbour
If you make a good-faith effort to follow this policy, we will not pursue legal action against you for your research and we will not report you to law enforcement for it. If a third party brings an action against you for research that followed this policy, we will make it known that your work was authorised.
Good faith means: you stopped as soon as you confirmed the issue; you did not access, download, alter or retain anyone else's data beyond the minimum needed to demonstrate the problem; you did not degrade the service for anyone else; and you gave us a reasonable chance to fix it before telling anyone else.
5. In scope
The Snapline iOS and iPadOS apps, the Snapline backend and API, share links served on our domains, and snapline.org.
6. Out of scope
Please do not do any of the following. They put real customers at risk and are not covered by the safe harbour above:
- Denial of service, load testing, or anything that degrades the service for others.
- Social engineering or phishing against our staff, our customers or our vendors, and any physical attempt against any of them.
- Accessing, modifying or deleting data in an organisation that is not yours. Use your own test organisation.
- Testing systems we do not operate. Our hosting, database, authentication, AI and push providers each run their own disclosure programmes; reports about their infrastructure belong there.
We generally do not treat the following as vulnerabilities on their own, though we read every report and will look again if you can show real impact:
- Missing security headers or weak TLS configuration with no demonstrated exploit.
- Automated scanner output with no analysis attached.
- The fact that a share link works without signing in. That is what a share link is for; the person who created it can revoke it. A way to guess or enumerate one is very much in scope.
- Issues requiring a physically compromised, jailbroken or unlocked device.
7. Recognition
We do not run a paid bounty programme today. We do say thank you properly, we credit researchers who want credit, and we will tell you honestly what we changed because of your report.