How to report
Write to support@casaconect.ai with “Security” at the start of the subject line, so that the report is recognized for what it is. Please include:- what you found, and where: the page, feature or address involved
- the steps needed to reproduce it
- what you believe an attacker could do with it
- whether you accessed any data in the course of finding it
- how we can reach you
If you are researching in good faith
We ask that you:- test only against accounts and organizations that are your own
- stop as soon as you have shown that the problem exists, and do not access, change or delete other people’s data
- avoid anything that degrades the service for others, such as denial-of-service testing, mass automated scanning, spam or social engineering of our staff and customers
- give us a reasonable opportunity to fix the problem before you describe it publicly
If you suspect unauthorized access to your organization
1
End suspicious sessions
Each affected person should open Settings → Security → Sessions and sign out any session they do not recognize. See Your account and sign-in.
2
Secure the mailbox
Sign-in codes go to email, so make sure the affected person’s email account is secure. Change its password and check its forwarding rules.
3
Add an authenticator app
Turn on two-factor authentication under Settings → Security.
4
Remove access you did not grant
An admin should review Settings → Members and pending invitations, and remove anyone who should not be there. Removal takes effect immediately.
5
Tell us
Write to us with what you saw and when. We can help you establish what happened.