Coordinated Security Disclosure
If you find a security issue in Ally, we want to hear about it. This page describes how to report responsibly.
Last updated: July 26, 2026
About this program
We appreciate security researchers who help make Ally safer for our users. This is a coordinated disclosure program, not a paid bug bounty. We do not currently offer monetary rewards, and we do not promise a specific response deadline. What we do commit to is acknowledging reports we receive, working with reporters in good faith, and being clear about what we can and cannot do.
If you would like to be credited for a valid report after we have shipped a fix, tell us in your report and we will follow up.
Scope
In scope
- Authentication and authorization issues
- Cross-site scripting (XSS)
- SQL or NoSQL injection
- Remote code execution (RCE)
- Server-side request forgery (SSRF)
- Insecure direct object references (IDOR)
- Sensitive data exposure
- API security issues
- Privilege escalation
- Business logic flaws with security impact
Out of scope
- Social engineering or phishing
- Denial of service (DoS/DDoS) testing
- Physical security issues
- Vulnerabilities in third-party services outside our control
- Self-XSS requiring user interaction on their own session
- Rate limiting without demonstrated security impact
- Missing security headers without demonstrated impact
- Outdated software without a demonstrable exploit
- Clickjacking on non-sensitive pages
- Username or email enumeration
Reporting guidelines
Guidelines for researchers
- 1Do not access, modify, or delete data belonging to other users
- 2Do not perform actions that could disrupt service availability
- 3Do not publicly disclose an issue before we have had reasonable time to investigate
- 4Submit one issue per report and provide clear reproduction steps
- 5Only test against accounts you own or have explicit permission to use
- 6Do not run automated scanners that generate excessive traffic
- 7Give us reasonable time to investigate and fix issues before follow-up
What to include in a report
Report contents
Required
- Clear description of the issue
- Step-by-step reproduction instructions
- Impact assessment
- Affected URLs, endpoints, or components
Helpful additions
- Proof-of-concept code or screenshots
- Video demonstration if applicable
- Suggested remediation
- Contact information for follow-up
Good-faith research
Our approach to researchers
If you follow the reporting guidelines above, act in good faith, and avoid impact to other users' data or the availability of the Service, we will treat your research as authorized for the purposes of reviewing your report. We reserve the right to make case-by-case judgments where activity extends beyond good-faith testing.
- We work with you in good faith to understand and resolve issues
- We can credit your contribution after a fix is deployed if you request it
- We aim to keep you informed as remediation progresses
Testing that touches other users' accounts or data without permission is not authorized and is not covered by this program.
Ready to report?
Email your report to our security team with as much detail as you can share.