Security
We value responsible reports that help protect Eagle Edge Software services and our users.
Report a vulnerability
Send your report to security@eagleedgesoftware.com. Please do not use the general contact form for security reports.
Include the affected service or URL, clear reproduction steps, the potential impact, and only the minimum proof needed to demonstrate the issue.
In scope
This policy covers Eagle Edge Software-operated public services, including:
- eagleedgesoftware.com, its public website pages, and website APIs.
- Public Eagle Edge Windows download pages and app-update endpoints.
- Eagle Edge-operated cloud services that support our products, where you have authorization to test them safely.
Out of scope
Third-party services and platforms are outside this policy, including Apple App Store, Google Play, Cloudflare, and vulnerabilities in third-party software that Eagle Edge does not operate.
Questions about app features, purchases, account access, or ordinary support belong at contact@eagleedgesoftware.com.
Test safely
Good-faith testing helps when it is careful and non-disruptive. Please do not:
- Access, modify, delete, or exfiltrate data that is not your own.
- Interrupt service, run denial-of-service tests, or use high-volume automated scanning.
- Use social engineering, phishing, or physical-security techniques.
- Publicly disclose a potential issue before giving us a reasonable opportunity to investigate and address it.
What to expect
We aim to acknowledge valid reports within three business days. We will investigate in good faith and share status updates when we have meaningful information to provide.
This policy does not offer financial rewards or authorize activity that is otherwise unlawful. We appreciate responsible reports that protect our users and services.