Vulnerability Disclosure Policy
Conversion Sciences takes the security of our systems and our clients’ data seriously. If you find a security weakness in anything we run, we want to hear about it. This page explains how to report it and what happens next.
How to Report a Vulnerability
Email security@conversionsciences.com. If you do not hear back, use managers@conversionsciences.com as a backup.
Please include:
- What you found and where you found it (the URL or system)
- Steps we can follow to reproduce it
- What an attacker could do with it
- Your contact information, if you want us to follow up
Screenshots or a short video help. Please do not include any personal data you may have seen.
What We Commit To
- We acknowledge your report within one business day.
- We send an initial assessment within three business days.
- We keep you updated while we fix the issue.
- If an issue affects one of our clients, we notify that client as soon as we confirm it.
- We tell you when the issue is resolved.
What This Policy Covers
- conversionsciences.com, our main website
- share.conversionsciences.com, where we host client reports and deliverables
- Test code we write and deploy on client websites for A/B and multivariate testing
- How we store and share client data in the tools we use, including access settings and shared links
What This Policy Does Not Cover
- Flaws in third-party platforms themselves, such as WordPress, Google, or our testing tools. Please report those to the vendor.
- Our clients’ own systems, apart from test code we deployed. Please report those to the client.
- Denial-of-service testing, spam, or anything that degrades service for others
- Social engineering, phishing, or physical attacks on our team or offices
Testing in Good Faith
We ask that you:
- Only test what you need to show the issue exists
- Do not access, change, or delete data that is not yours. If you reach client or personal data by accident, stop and tell us.
- Give us reasonable time to fix the issue before you share it publicly
- Do not demand payment in exchange for details
If you follow these guidelines, we will not pursue legal action against you for your research, and we will work with you to understand and fix the problem.
Recognition
We do not run a paid bug bounty. With your permission, we are happy to thank you publicly once the issue is fixed.
Machine-Readable Contact
Our contact details are also published in our security.txt file, which follows RFC 9116.
Last updated: October 2026






