If you found a way to reach something in MBX Reach that you should not be able to reach, this page tells you how to tell us and what happens next.
Unlike the other three documents here, this one is not part of the agreement with our customers. It is a standing invitation to anyone who finds a defect, and a promise about how we will treat you for reporting it.
1.How to Report Something
Write to support@mbxreach.com with the subject line starting SECURITY. Tell us what you found, the exact steps to reproduce it, what you were able to reach, and how you would like to be credited if we publish a fix. A short screen recording is worth three paragraphs.
If a report involves personal data you were able to see, say so in the first line so we can treat it as an incident from the start.
This address is for security defects in MBX Reach itself. If you received a message you did not ask for that was sent through MBX Reach, that is not a security report: use the unsubscribe link, and write to abuse@mbxreach.com to report the sender.
2.What We Promise You
- we acknowledge every report within three working days, from a person, not an autoresponder;
- we tell you what we found, whether we agree it is a defect, and when it is fixed;
- we will not take legal action, or ask anyone else to, over research done in good faith under the rules below, even if it turns out you were wrong about the finding;
- we credit you by the name you choose when we publish a fix, or stay quiet about you entirely if you prefer.
We do not run a paid bounty programme. We would rather say that plainly than let you spend a weekend expecting one.
3.The Rules
Good faith means all of these:
- use your own account and your own test data; do not touch another customer's workspace, contacts or campaigns;
- stop at the first proof. If you can read one record that is not yours, you have proved it; do not go and read the rest;
- do not modify or delete anything that is not yours, and do not keep any personal data you came across; tell us instead;
- no denial of service, no volumetric or stress testing, and no automated scanning heavy enough to slow the service for anyone else;
- no social engineering of our people, our customers or our suppliers, and nothing physical;
- give us reasonable time to fix a defect before you tell anyone else about it.
5.Out of Scope
These get a polite answer rather than a fix, so we would rather you spend the time elsewhere:
- output from an automated scanner with no working proof of impact;
- a missing header, a cookie flag or a TLS configuration opinion with no exploit behind it;
- reports that a rate limit exists, or that a rate limit can be reached;
- the content of email our customers send, which is the Anti-Spam & Acceptable Use Policy's subject, not this page's;
- defects in infrastructure we do not run, which we will pass upstream but cannot fix;
- anything that requires a person to already hold the victim's password, device or recovery codes.