Leash
🧩 Features📚 Docs✍️ Blog💸 Pricing
Sign in
Security

Report a security issue

Last updated: September 2, 2026

Private reporting channel

Email security@openleash.com with a concise description, affected product or URL, steps to reproduce, potential impact, and any safe proof of concept. Do not include real customer secrets, personal data, or destructive payloads.

Scope

Reports may cover the Leash website, hosted Cloud services, authentication and account flows, official desktop or mobile clients, and code in the public Leash repository. Third-party services, social engineering, denial-of-service testing, spam, and activity that accesses data you do not own or have permission to test are out of scope.

Safe testing

  • Use accounts, devices, and data you own or are explicitly authorized to test.
  • Stop if you encounter another person's data or could degrade service availability.
  • Do not retain, transfer, alter, or publicly disclose data obtained during testing.
  • Give us a reasonable opportunity to investigate and address a valid issue before publication.

What happens next

We will review the report, ask for clarification when needed, assess product impact, and coordinate remediation and disclosure directly with the reporter. Response timing depends on severity, clarity, reproducibility, and current operational capacity; this page does not promise a paid bounty or fixed SLA.

Public references

  • security.txt
  • Trust Center
  • Public Leash repository
  • Privacy Policy