We welcome reports of security vulnerabilities in Plethos and Gushwork systems. If you find one, please tell us so we can fix it.
How to report
Email admin@gushwork.ai with the subject "Security report" and include:
- a description of the issue and where it is (URL, endpoint or component);
- steps to reproduce it, and a proof of concept if you have one;
- the impact you believe it has;
- how to reach you for follow-up.
Please don't include real client data or leads in your report. For privacy requests, see the Privacy Policy.
In scope
- plethos.gushwork.ai and its pages
- The Plethos dashboard at app.gushwork.ai
- The Plethos app on Meta, including its login and data deletion callbacks
- Plethos APIs and webhooks
Out of scope
- Meta's platforms. Report those to Meta's bug bounty program.
- Denial-of-service attacks, spam, or load testing
- Social engineering or phishing of our staff or clients
- Physical attacks on offices or data centers
- Reports from automated scanners without a demonstrated impact
- Missing best-practice headers or settings with no demonstrated security impact
Our response
| Step | Timeframe |
|---|---|
| We confirm receipt | Within 3 business days |
| We share our assessment | Within 10 business days |
| We fix confirmed issues | Based on severity; critical issues are prioritized immediately |
| We tell you when it's fixed | When the fix is live |
Safe harbor
If you act in good faith and follow this policy, we will not take legal action against you or ask law enforcement to investigate you. Acting in good faith means you:
- only access the data you need to show the issue, and don't keep, share or change it;
- stop and tell us straight away if you reach client data or leads;
- don't degrade our services or harm our clients;
- give us reasonable time to fix the issue before telling anyone else.
Contact
Security reports: admin@gushwork.ai (subject "Security report")
Regents Inc dba Gushwork, 16192 Coastal Hwy, Lewes, DE 19958, United States