Security Response by Basecamp

Updated 17 October 2025

This document outlines a company's approach to security, detailing how customer data is protected and how security concerns are handled. It provides clear channels for customers to report account attacks and for security researchers to disclose vulnerabilities through a bug bounty program. The company commits to investigating and resolving issues, ensuring proper credit for discoveries.

Security response

We appreciate your concern

Keeping customer data safe and secure is a huge responsibility and a top priority. We work hard to protect our customers from the latest threats. Your input and feedback on our security is always appreciated.

Reporting security problems

If you are a HEY customer and your account is under an attack such as hacking or mailbombing, send us an email at [email protected]. We will respond within two hours and work with you to counter the attack.

Report security vulnerabilities via our bug bounty program on HackerOne. We’ll review your report and get back to you as soon as we can, usually within 72 hours. Please email our [Security team]({{ site.email_security }}) if you have questions about the bug bounty program or don’t hear back from us on HackerOne in a timely manner.

For other urgent or sensitive reports, please email our [Security team]({{ site.email_security }}). We’ll respond as soon as we can.

For requests that aren’t urgent or sensitive: submit a [support request]({{ site.email_support }}).

Tracking and disclosing security issues

We work with security researchers to keep up with the state-of-the-art in web security. Have you discovered a web security flaw that might impact our products? Please let us know. If you submit a report, here’s what will happen:

We’ll acknowledge your report.

We’ll triage your report and determine whether it’s eligible for a bounty.

We’ll investigate the issue and determine how it impacts our products. We won’t disclose issues until they’ve been fully investigated and patched, but we’ll work with you to ensure we fully understand severity and impact.

Once the issue is resolved, we’ll post a security update along with thanks and credit for the discovery.

Our products are built on the Ruby on Rails framework (which we created and maintain). The issue you reported might affect Rails, Ruby, or some other part of our technology stack. We ask for your patience while we also make sure other companies and their customers are protected. Either way, you’ll always have a 37signals contact for your issue.

Thanks for working with us

We respect the time and talent that drives new discoveries in web security technology. The following researchers and companies have gone out of their way to work with us to find, fix, and disclose security flaws safely:

Brett Hardin

Brian Mastenbrook

Clouds

Emanuel Bronshtein

Jeremy Mack

John Firebaugh

Kamil Sevi

Marko Karppinen

Matasano Security

MustLive

Nathan Kontny

nGenuity Information Services

ONZRA

Óscar Repáraz

Rakan Alotaibi @hxteam

Simon Brown

Tim Bach

Jan Habermann

John Menerick

Prajal Kulkarni

Ajay Singh Negi

Harsha Vardhan Boppana (Login Security Solution (P) Limited)

Frans Rosén

Rafay Baloch

M.R. Vignesh Kumar

Himanshu Kumar Das

Krutarth Shukla

Ahmad Ashraff

InverseKey

Adino Namchu

Atulkumar Hariba Shedage

West Arete

Abhinav Karnawat / w4rri0r /

Mahadev subedi

Vedachala

Ehraz Ahmed

Umraz Ahmed

Ahsan Akhtar

Jose Pino

Priyal Viroja

Chris Raethke (Bugcrowd)

Siddhesh Gawde

Vinesh N. Redkar

Swapnil Thaware

Hammad Shamsi

Saurabh Chandrakant Nemade

Nitin Goplani

Sahil Saif

Rafael Pablos

Nutan Kumar Panda

Koutrouss Naddara

Gurjant Singh

Mayank Kapoor

FailHunters Crew

Daniel Alvear(MaztoR IN-Security)

Ali Hassan Ghori (@alihasanghauri)

Rodolfo Godalle Jr.

Simone Memoli

Daksh Patel

Jovan Šikanja

Muhammad Talha Khan

Yash Pandya

Mark Dodwell

Gabe Marshall

Matt Jaynes

Nakul Mohan (@Anonymous_India)

Hardik Tailor

Marques Johansson

Rishiraj Sharma

Yogendra Sharma

Prashant Padmashali

Apoorv Joshi

Shivam Kumar Agarwal, Nithish Varghese, and Sahil Srivastava

Shahmeer Amir

Hamid Ashraf

Babar Khan Akhunzada

Ramin Farajpour Cami

Yassine Aboukir

Vikas Anil Sharma

Gaurang Bhatnagar

Ahmed Adel Abdelfattah

Sumit Sahoo

Vishnu Prasanth G

Ashish Padelkar

Hazim Aslam

Bram Gagliardi (securibee)

About this template

What is this template?

Security Response by Basecamp is a free, ready-to-use Cybersecurity template you can open, customize, and download on GitLaw. It gives you a professionally structured starting point, so you never have to draft from a blank page. The wording is plain and modern, organized into clear sections that are easy to read, edit, and adapt to your own situation before you share or sign it.

When should you use it?

Reach for this Cybersecurity template whenever you need a reliable agreement quickly and want to be sure the essentials are covered. It suits individuals, freelancers, startups, and established businesses alike. Instead of paying for a document drafted from scratch, you can start here, tailor the details to your arrangement, and have a polished draft ready in minutes. Always review the final wording against the laws that apply where you live or do business.

What's typically included?

A well-drafted Cybersecurity usually sets out the parties involved, the scope of the agreement, and each side's rights and responsibilities. Expect sections covering key terms and definitions, how long the agreement lasts, how it can be ended, and what happens if something goes wrong. This template brings those building blocks together in a sensible order, so you can focus on the specifics rather than worrying about what to include. Open it to read the full document, then sign up to edit, negotiate, and e-sign it directly in GitLaw.

Jurisdiction
Jurisdictions aren't set for this document
Document info
HTML document. Document created on Thu Sep 11th, 2025. Last updated on Fri Oct 17th, 2025.
This document is public
Licensed under CC BY 4.0 (Attribution).
Come to agreements faster
Write, review, negotiate, and manage legal contracts
Related documents
OLOpen Legal Library
Pocket Privacy Policy by Mozilla
OLOpen Legal Library
Cell Phone Policy by EasyLegalDocs
OLOpen Legal Library
Sample Code of Conduct Policy (NVCA)
OLOpen Legal Library
Anti-Bribery and Corruption Policy by EasyLegalDocs
OLOpen Legal Library
Privacy Policy by EasyLegalDocs
OLOpen Legal Library
Anti Slavery Policy by EasyLegalDocs