PhoneHQ (Crazy Call Sp. z o.o.) takes security seriously. If you find a security vulnerability in our services, we want to hear about it — and we want to make sure that reporting it in good faith never exposes you to legal consequences from us.
Reporting address: security@phonehq.com
Please include: a description of the vulnerability, steps to reproduce, potential impact, and a proof of concept (where possible without compromising user privacy). Reports in English or Polish are welcome.
In scope:
Out of scope:
We will not take legal action against, or report to law enforcement, researchers who act in good faith, do not violate user privacy, do not destroy data, do not disrupt our services, and report the vulnerability only to us, giving us reasonable time to fix it before any public disclosure.
Acknowledgement of your report: within 3 business days.
Initial assessment (whether it is a valid vulnerability and its severity): within 7 business days.
We ask for coordinated disclosure: you may publish details only after the vulnerability has been fixed or 90 days after your report (whichever comes first), unless we agree on a different timeline.
PhoneHQ does not currently run a bug bounty programme (no financial rewards for reports). We value every report and, with your consent, are happy to thank you publicly.
Up-to-date information on cyber threats is published by CSIRT NASK (the Polish national CSIRT): https://cert.pl.