Skip to main content

    Coordinated Security Disclosure

    If you find a security issue in Ally, we want to hear about it. This page describes how to report responsibly.

    Last updated: July 26, 2026

    About this program

    We appreciate security researchers who help make Ally safer for our users. This is a coordinated disclosure program, not a paid bug bounty. We do not currently offer monetary rewards, and we do not promise a specific response deadline. What we do commit to is acknowledging reports we receive, working with reporters in good faith, and being clear about what we can and cannot do.

    If you would like to be credited for a valid report after we have shipped a fix, tell us in your report and we will follow up.

    Scope

    In scope

    • Authentication and authorization issues
    • Cross-site scripting (XSS)
    • SQL or NoSQL injection
    • Remote code execution (RCE)
    • Server-side request forgery (SSRF)
    • Insecure direct object references (IDOR)
    • Sensitive data exposure
    • API security issues
    • Privilege escalation
    • Business logic flaws with security impact

    Out of scope

    • Social engineering or phishing
    • Denial of service (DoS/DDoS) testing
    • Physical security issues
    • Vulnerabilities in third-party services outside our control
    • Self-XSS requiring user interaction on their own session
    • Rate limiting without demonstrated security impact
    • Missing security headers without demonstrated impact
    • Outdated software without a demonstrable exploit
    • Clickjacking on non-sensitive pages
    • Username or email enumeration

    Reporting guidelines

    Guidelines for researchers

    • 1Do not access, modify, or delete data belonging to other users
    • 2Do not perform actions that could disrupt service availability
    • 3Do not publicly disclose an issue before we have had reasonable time to investigate
    • 4Submit one issue per report and provide clear reproduction steps
    • 5Only test against accounts you own or have explicit permission to use
    • 6Do not run automated scanners that generate excessive traffic
    • 7Give us reasonable time to investigate and fix issues before follow-up

    What to include in a report

    Report contents

    Required

    • Clear description of the issue
    • Step-by-step reproduction instructions
    • Impact assessment
    • Affected URLs, endpoints, or components

    Helpful additions

    • Proof-of-concept code or screenshots
    • Video demonstration if applicable
    • Suggested remediation
    • Contact information for follow-up

    Good-faith research

    Our approach to researchers

    If you follow the reporting guidelines above, act in good faith, and avoid impact to other users' data or the availability of the Service, we will treat your research as authorized for the purposes of reviewing your report. We reserve the right to make case-by-case judgments where activity extends beyond good-faith testing.

    • We work with you in good faith to understand and resolve issues
    • We can credit your contribution after a fix is deployed if you request it
    • We aim to keep you informed as remediation progresses

    Testing that touches other users' accounts or data without permission is not authorized and is not covered by this program.

    Ready to report?

    Email your report to our security team with as much detail as you can share.