Report a Vulnerability
Voice2Jobs holds contractors' customer lists, quotes, invoices, and payment connections. If you have found a way to reach data or functionality you should not be able to reach, we want to hear about it, and we would rather hear it from you than from a customer.
1. How to Report
Email security@voice2jobs.com. Please include:
- What the issue is, and what an attacker could do with it.
- Clear steps to reproduce it. A short recording or a request and response pair is ideal.
- The URL, endpoint, or screen involved, and roughly when you found it.
- Any account you used. If you needed a test account, say so and we will confirm it was yours.
Please report in English where you can, and please do not open a public issue, post publicly, or contact individual staff members before we have replied.
2. What We Commit To
- We acknowledge reports within 3 business days.
- We give you an initial assessment, including whether we consider it in scope and how severe we think it is, within 10 business days.
- We keep you updated while we work on a fix, and we tell you when it ships.
- We will credit you by name when we publish anything about the issue, if you want that. Tell us how you would like to be named, or tell us you would rather not be.
3. Safe Harbour
If you make a good-faith effort to follow this policy, we will not pursue legal action against you for your research, and we will not report you to law enforcement for it. If a third party brings action against you for research that followed this policy, we will make it known that your work was authorised.
Good faith means: you stopped as soon as you confirmed the issue, you did not access, download, alter, or retain anyone else's data beyond the minimum needed to demonstrate the problem, you did not degrade the service for anyone else, and you gave us a reasonable chance to fix it before telling anyone else.
4. Out of Scope
Please do not do any of the following. They put real customers at risk and they are not covered by the safe harbour above:
- Denial of service, load testing, or anything that degrades the service for others.
- Social engineering, phishing, or physical attempts against our staff, our customers, or our vendors.
- Accessing, modifying, or deleting data belonging to a real account that is not yours. Use your own test account.
- Testing systems we do not operate. Our payment processing, hosting, database, email, and AI providers each run their own disclosure programmes, and reports about their infrastructure should go to them.
We generally do not treat the following as vulnerabilities on their own, though we still read every report and will look again if you can show real impact:
- Missing security headers, or weak TLS configuration, with no demonstrated exploit.
- Output from an automated scanner with no analysis attached.
- Self-inflicted issues that require the victim to paste code into their own browser console.
- Email configuration findings such as SPF, DKIM, or DMARC records, absent a working spoofing demonstration.
- Rate limiting on endpoints that do not send messages, move money, or expose data.
5. Rewards
We do not currently run a paid bug bounty. We are a small team and we would rather promise a fast, honest response and public credit than advertise a reward we cannot administer consistently. If you report something serious, we will tell you so, fix it quickly, and say thank you properly.
6. If You Are a Customer
If you think your own account has been accessed by someone else, do not wait for this process. Change your password immediately, then write to security@voice2jobs.com and tell us what you saw. If you believe a person is misusing Voice2Jobs against you or your customers, rather than exploiting a flaw in it, that belongs under our Acceptable Use Policy.
7. Breach Notification
If a security incident affects personal data we process on a customer's behalf, we notify that customer without undue delay, as set out in our Data Processing Agreement. How we handle personal data generally is described in our Privacy Policy.