Responsible Security Disclosure
If you believe you found a security or privacy issue involving a State of Stick site, connected experience, customer portal, or object workflow, report it privately.
Include
Section titled “Include”- A concise description of the issue
- The affected public URL or product context
- The date and approximate time observed
- Reproduction steps that do not expose another person’s data
- Screenshots with personal information and tokens removed
- Your preferred contact method
Do not
Section titled “Do not”- Access, change, download, or retain data that is not yours
- Test against customer production records without written authorization
- Attempt denial of service, social engineering, credential attacks, or physical intrusion
- Publish private links, session values, secure-tag material, or personal information
- Demand payment or threaten disclosure
Send the report through the contact method published in the site’s security.txt. We will acknowledge good-faith reports, assess impact, preserve relevant evidence, and coordinate an appropriate response.
This page does not create authorization to test systems or a promise of payment.