> ## Documentation Index
> Fetch the complete documentation index at: https://help.casaconect.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Reporting a security concern

> How to report a suspected vulnerability or a security incident affecting your organization.

We welcome reports from customers and security researchers. If you think you have found a weakness in Casa Conect, or you suspect that someone has accessed your organization without permission, tell us as soon as you can.

## How to report

Write to **[support@casaconect.ai](mailto:support@casaconect.ai)** with **"Security"** at the start of the subject line, so that the report is recognized for what it is.

Please include:

* what you found, and where: the page, feature or address involved
* the steps needed to reproduce it
* what you believe an attacker could do with it
* whether you accessed any data in the course of finding it
* how we can reach you

<Warning>
  Do not put passwords, access tokens or client documents in your report. If you need to share something sensitive in order to demonstrate the problem, say so, and we will arrange a suitable channel.
</Warning>

## If you are researching in good faith

We ask that you:

* test only against accounts and organizations that are **your own**
* stop as soon as you have shown that the problem exists, and do not access, change or delete other people's data
* avoid anything that degrades the service for others, such as denial-of-service testing, mass automated scanning, spam or social engineering of our staff and customers
* give us a reasonable opportunity to fix the problem before you describe it publicly

## If you suspect unauthorized access to your organization

<Steps>
  <Step title="End suspicious sessions">
    Each affected person should open **Settings → Security → Sessions** and sign out any session they do not recognize. See [Your account and sign-in](/admin/account-and-sign-in).
  </Step>

  <Step title="Secure the mailbox">
    Sign-in codes go to email, so make sure the affected person's **email account** is secure. Change its password and check its forwarding rules.
  </Step>

  <Step title="Add an authenticator app">
    Turn on two-factor authentication under **Settings → Security**.
  </Step>

  <Step title="Remove access you did not grant">
    An admin should review **Settings → Members** and pending invitations, and remove anyone who should not be there. Removal takes effect immediately.
  </Step>

  <Step title="Tell us">
    Write to us with what you saw and when. We can help you establish what happened.
  </Step>
</Steps>
