Vulnerability Disclosure Policy (VDP)

PhoneHQ (Crazy Call Sp. z o.o.) takes security seriously. If you find a security vulnerability in our services, we want to hear about it — and we want to make sure that reporting it in good faith never exposes you to legal consequences from us.

How to report a vulnerability

Reporting address: security@phonehq.com

Please include: a description of the vulnerability, steps to reproduce, potential impact, and a proof of concept (where possible without compromising user privacy). Reports in English or Polish are welcome.

Scope

In scope:

Out of scope:

Safe harbour

We will not take legal action against, or report to law enforcement, researchers who act in good faith, do not violate user privacy, do not destroy data, do not disrupt our services, and report the vulnerability only to us, giving us reasonable time to fix it before any public disclosure.

Response times

Acknowledgement of your report: within 3 business days.
Initial assessment (whether it is a valid vulnerability and its severity): within 7 business days.

Public disclosure

We ask for coordinated disclosure: you may publish details only after the vulnerability has been fixed or 90 days after your report (whichever comes first), unless we agree on a different timeline.

Bug bounty

PhoneHQ does not currently run a bug bounty programme (no financial rewards for reports). We value every report and, with your consent, are happy to thank you publicly.

Current cyber threat information

Up-to-date information on cyber threats is published by CSIRT NASK (the Polish national CSIRT): https://cert.pl.