Our security program

SitePath Intelligence LLC treats the security of our platform and the confidentiality of customer data as core to the product. This page summarizes the controls we operate and how to responsibly report a security issue.

How we protect data

For the list of third-party subprocessors that may process personal data on our behalf, and the safeguards governing international transfers, see our Data Processing Addendum (Schedule 3) and Privacy Policy.

Coordinated vulnerability disclosure

We welcome reports from security researchers and will work with you in good faith to verify and remediate legitimate issues.

How to report

Please do

Please do not

Safe harbor

If you make a good-faith effort to comply with this policy during your research, we will consider your testing authorized, will not pursue or support legal action against you for it, and will work with you to understand and resolve the issue quickly. This policy does not authorize actions that violate applicable law.

We do not currently operate a paid bug-bounty program, but we are glad to acknowledge researchers who responsibly disclose valid issues.

Reporting a data incident

If you believe your account or personal data has been compromised, email support@sitepathintel.com immediately with the subject line "Security Report". Our breach-notification commitments to customers are described in our Data Processing Addendum.