Security Response by Basecamp

BasecampUpdated 17 Oct 2025

This document outlines a company's approach to security, detailing how customer data is protected and how security concerns are handled. It provides clear channels for customers to report account attacks and for security researchers to disclose vulnerabilities through a bug bounty program. The company commits to investigating and resolving issues, ensuring proper credit for discoveries.

Security response

We appreciate your concern

Keeping customer data safe and secure is a huge responsibility and a top priority. We work hard to protect our customers from the latest threats. Your input and feedback on our security is always appreciated.

Reporting security problems

If you are a HEY customer and your account is under an attack such as hacking or mailbombing, send us an email at [email protected]. We will respond within two hours and work with you to counter the attack.

Report security vulnerabilities via our bug bounty program on HackerOne. We’ll review your report and get back to you as soon as we can, usually within 72 hours. Please email our [Security team]({{ site.email_security }}) if you have questions about the bug bounty program or don’t hear back from us on HackerOne in a timely manner.

For other urgent or sensitive reports, please email our [Security team]({{ site.email_security }}). We’ll respond as soon as we can.

For requests that aren’t urgent or sensitive: submit a [support request]({{ site.email_support }}).

Tracking and disclosing security issues

We work with security researchers to keep up with the state-of-the-art in web security. Have you discovered a web security flaw that might impact our products? Please let us know. If you submit a report, here’s what will happen:

We’ll acknowledge your report.

We’ll triage your report and determine whether it’s eligible for a bounty.

We’ll investigate the issue and determine how it impacts our products. We won’t disclose issues until they’ve been fully investigated and patched, but we’ll work with you to ensure we fully understand severity and impact.

Once the issue is resolved, we’ll post a security update along with thanks and credit for the discovery.

Our products are built on the Ruby on Rails framework (which we created and maintain). The issue you reported might affect Rails, Ruby, or some other part of our technology stack. We ask for your patience while we also make sure other companies and their customers are protected. Either way, you’ll always have a 37signals contact for your issue.

Thanks for working with us

We respect the time and talent that drives new discoveries in web security technology. The following researchers and companies have gone out of their way to work with us to find, fix, and disclose security flaws safely:

Brett Hardin

Brian Mastenbrook

Clouds

Emanuel Bronshtein

Jeremy Mack

John Firebaugh

Kamil Sevi

Marko Karppinen

Matasano Security

MustLive

Nathan Kontny

nGenuity Information Services

ONZRA

Óscar Repáraz

Rakan Alotaibi @hxteam

Simon Brown

Tim Bach

Jan Habermann

John Menerick

Prajal Kulkarni

Ajay Singh Negi

Harsha Vardhan Boppana (Login Security Solution (P) Limited)

Frans Rosén

Rafay Baloch

M.R. Vignesh Kumar

Himanshu Kumar Das

Krutarth Shukla

Ahmad Ashraff

InverseKey

Adino Namchu

Atulkumar Hariba Shedage

West Arete

Abhinav Karnawat / w4rri0r /

Mahadev subedi

Vedachala

Ehraz Ahmed

Umraz Ahmed

Ahsan Akhtar

Jose Pino

Priyal Viroja

Chris Raethke (Bugcrowd)

Siddhesh Gawde

Vinesh N. Redkar

Swapnil Thaware

Hammad Shamsi

Saurabh Chandrakant Nemade

Nitin Goplani

Sahil Saif

This is a preview. The full template is free on GitLaw.

5.0 out of 5 on Google

Read reviews

As seen in

Law360
Artificial Lawyer
Insider
Axios Pro
San Francisco Business Times
Built In
Startups Magazine
Business Reporter
Tech.eu
Jurisdiction
Jurisdictions aren't set for this document
Document info
HTML document. Document created on Thu Sep 11th, 2025. Last updated on Fri Oct 17th, 2025.
This document is public
Licensed under CC BY 4.0 (Attribution).
Come to agreements faster
Write, review, negotiate, and manage legal contracts
Related documents
US
Security Policies Github Sirt Description Rfc 2350 (GitHub)
This document provides a standardized description of a Computer Security Incident Response Team (CSIRT) following the RFC 2350 protocol. It details contact methods, the team's mission and authority, and specific procedures for handling security incidents.
Updated 13 Aug 2026
US
Security Policies Coordinated Disclosure Of Security Vulnerabilities (GitHub)
This policy establishes a framework for security researchers to find and report vulnerabilities in a company's software. It introduces a bug bounty program that offers financial rewards for coordinated disclosure and provides links to specific legal safe harbor terms.
Updated 13 Aug 2026
Denmark
Privacy Policy (Denmark) by Seedsummit
This internal data protection policy establishes how a company manages personal information in compliance with the EU General Data Protection Regulation. It defines processing principles such as data minimization and storage limitation, and outlines the responsibilities of a designated IT systems administrator in Denmark.
Updated 13 Aug 2026
England & Wales
Firefox Focus and Firefox Klar Privacy Notice by Mozilla
This privacy notice explains how a browser developer processes technical, interaction, and browsing data. It details user rights under data protection laws and provides options for managing data collection and search preferences.
Updated 13 Aug 2026
General
Other Site Policies Github Account Recovery Policy (GitHub)
This policy explains the methods and limitations for regaining access to a user or organization account, specifically addressing two-factor authentication. It clarifies that staff cannot manually restore access if all automated recovery methods and security credentials have been lost.
Updated 13 Aug 2026
US
VPN Privacy Notice by Mozilla
This privacy notice explains how a VPN service handles user data, encryption, and third-party sharing. It details the collection of account info, approximate location via IP address, and limited billing details from providers like Stripe or Apple.
Updated 13 Aug 2026

Frequently asked questions

A template isn't binding on its own - like any contract, it becomes binding once it's properly completed and signed. Templates in our curated library are professionally drafted for US or UK law; review any template before you sign it.

Yes. Chat with GitLaw to edit any section, or make changes directly in the editor.

Yes, read about team plans here.

Describe what you need in the chat and GitLaw will draft it for you.

Templates in our curated library are professionally drafted for US or UK law. The wider library comes from the GitLaw community and public sources - a solid starting point, but check any template fits your situation before you rely on it.

Mostly US and UK law. Some templates use general commercial terms that work across jurisdictions, and many note which law they're written for.

It depends on the situation. Templates work well for routine business agreements. For anything involving significant money, complex IP, employment, or areas you're unsure about, it's worth getting professional advice before you sign. GitLaw provides templates and tools, not legal advice.

Open any template in GitLaw and describe the change you want in the chat — 'make clause 4 mutual' or 'add a 30-day notice period', for example. GitLaw drafts the revised language and shows it as a suggested edit. You accept, reject, or keep editing from there.

Yes. Upload a Word, PDF, or Markdown file and GitLaw will open it in the editor. You can review, edit, or chat with GitLaw about it the same way you would with any template from the library.

Trusted by 5,000+ businesses

Nexus logoMlabs logoTechstars logo

From template to signed, in one place

Every template opens in an editor with an AI agent alongside it.

1

Open

Pick a template and open it. Nothing to download, and no credit card to start.

Free to open

2

Edit with AI

Describe your situation in chat and the agent adapts the wording, clause by clause.

Tracked changes you can review

3

Send and sign

Share it for negotiation, then collect signatures without leaving GitLaw.

eSign included

Built for your legal work,
with practicing lawyers

Trained on 5,500+ clauses and specialist areas of law. Built with a standards committee of independent lawyers.

As seen in

Law360
Artificial Lawyer
Insider
Axios Pro
San Francisco Business Times
Built In
Startups Magazine
Business Reporter
Tech.eu

Ready to get started?

No sales calls, no credit card. Just chat with GitLaw.

GitLaw provides templates and tools, not legal advice. Templates are a starting point, not a substitute for advice on your situation - for anything significant, speak to a qualified lawyer.