Overview
Spellbook welcomes good-faith security research and reports of potential vulnerabilities. This Vulnerability Disclosure Program (VDP) describes how to submit a report and how we triage, validate, and respond.
We appreciate the time and effort researchers invest in helping us keep Spellbook secure.
Scope
This VDP applies to:
- Spellbook-owned web applications and APIs in production.
- In scope, Spellbook-owned domains and subdomains:
- associate.spellbook.legal
- api.spellbook.legal
- word-add-in.spellbook.legal
- gdocs-add-in.spellbook.legal
- associate-editor.spellbook.legal
Out of scope:
- Third-party services not controlled by Spellbook.
- Social engineering (phishing, vishing, AI impersonation), physical security, or denial-of-service testing.
- Automated scanning that materially degrades service availability.
Safe harbor (good-faith research)
Research conducted in good-faith compliance with this policy is authorized access to the systems in scope. We will not pursue legal action for that good-faith research. If a third party brings action against you for policy-compliant research, we will make known that your activity was authorized.
We cannot authorize testing against systems we do not own. Therefore, this safe harbor does not extend to, and does not bind, third-party infrastructure, subprocessors, or services. It also does not apply to activity outside this policy.
Good-faith research means:
- You only test within scope.
- You do not target Spellbook customers, customer environments, or customer data.
- You use your own test accounts and test data whenever possible.
- You avoid privacy violations and do not access, modify, or delete data beyond what is necessary to demonstrate the issue.
- You stop testing and promptly report if you encounter sensitive data.
- You do not exploit an issue beyond what is necessary to confirm its existence.
- You keep any Spellbook or customer data you encounter confidential, delete it once you have reported, and confirm deletion on request.
- You tell us immediately if you access personal data, and cooperate reasonably so we can meet any notification obligations.
- You do not condition a report on payment or threaten disclosure. Reports made on those terms are not good faith and forfeit this safe harbor.
How to report
Please send reports to: vdp@spellbook.com
Include:
- A clear description of the issue and the affected asset/URL.
- Steps to reproduce and a proof-of-concept (as safe as possible).
- Impact assessment (what an attacker could do).
- Any relevant logs, screenshots, request/response samples.
What you can expect from us
- We will attempt to acknowledge receipt within 7 business days.
- We will triage the report and determine whether it is valid, in scope, and actionable.
- If valid, we will work to remediate in a reasonable timeframe based on severity and complexity.
Triage and validation process
To help us review reports efficiently and focus on actionable issues, we use the process below.
1) Intake
We log each report and assign an internal owner.
2) Initial screening (fast check)
We may close a report without further investigation if it is clearly one of the following:
- Not a security vulnerability or is intended behavior (e.g., missing security headers that are not relevant to our threat model).
- No repro provided and the report is only a general claim with no specific affected asset, steps, or evidence.
- Security impact not demonstrated or the report does not clearly explain a realistic security impact.
- Out of scope as defined above.
- Known issue / duplicate (already reported or already tracked internally). Duplicate reports may be closed, but we still appreciate the submission.
- Unvalidated automated scanner output (generic automated output without validation).
If we close a report at this stage, we may reply with a brief reason (e.g., “out of scope” or “unable to reproduce with details provided”). For reports that lack sufficient detail, we may be unable to provide detailed follow-up beyond a brief closure reason.
3) Request for more information (if needed)
If the report might be valid but lacks key details, we may request:
- Exact affected endpoint/asset
- Exact request/response examples
- Steps to reproduce from a clean environment
- Clarification on impact
If we do not receive the requested information within 14 days, we may close the report as insufficient information.
4) Reproduction and impact assessment
If we can reproduce the issue, we will assess severity and prioritize remediation.
5) Remediation and closure
We will track remediation internally and close the report when:
- The issue is fixed, mitigated, or accepted as risk; or
- We determine the report is not a vulnerability.
Rewards / bounty
Spellbook does not currently offer a paid bug bounty.
Legal notes
- This document supports vulnerability reporting and response coordination on Spellbook systems. It does not create a contractual obligation toward, or offer compensation to, any participant in the Vulnerability Disclosure Program.
- The program is provided as-is. We make no commitment to any particular remediation timeline or outcome.
- By submitting a report, you (a) grant Spellbook a perpetual, worldwide, royalty-free licence to use it, and (b) confirm it contains no third-party confidential information.
- You are not eligible to participate if you are resident in a sanctioned jurisdiction or listed on an applicable denied-party list, or if you are a current or former Spellbook employee or contractor.
- We may amend this program policy at any time. The version in effect when you test is the version that applies.
- Governing law: Toronto, Ontario, Canada.
Questions
Contact: vdp@spellbook.com