Skip to main content

Security

Vulnerability Disclosure

LEADOXE CRM is owned and operated by VEYSAPP LLC. We welcome good-faith reports that help us investigate potential security issues responsibly.

Effective date: July 29, 2026

How to report

Email security@leadoxe.com with a clear description, the affected URL or feature, reproducible steps, observed impact, and non-sensitive evidence. Do not include passwords, raw access tokens, private keys, or unnecessary personal data.

Research boundaries

Do not access, modify, delete, download, or retain data that is not yours; disrupt service; use social engineering; test third-party providers; perform denial-of-service activity; or continue testing after identifying a vulnerability. Intrusive testing requires advance written authorisation.

What happens next

We will assess credible reports, may request clarification, and will prioritise remediation according to verified risk. Response and remediation times depend on severity, reproducibility, dependencies, and operational constraints; this page does not create a fixed response deadline.

Confidentiality and disclosure

Please allow reasonable time for investigation and remediation before any public disclosure. Coordinate disclosure with us so customer security is not placed at additional risk. This policy does not authorise conduct prohibited by law or by a third-party provider.

Encryption and rewards

A public PGP key is not currently published. Contact the security address first if a protected transfer channel is needed. LEADOXE does not currently promise a bug bounty or payment; any recognition or reward requires separate written confirmation.

Vulnerability Disclosure | LEADOXE CRM