Security & Responsible Disclosure
We take the security of our website, apps and advertising API integrations seriously.
Website security
- This website is served exclusively over HTTPS, with automatic redirection from HTTP.
- We apply security-related HTTP response headers, including HSTS, a Content Security Policy, X-Content-Type-Options, a Referrer-Policy, a Permissions-Policy and frame protection.
- No API credentials, developer tokens, or account secrets are stored in this website's front-end code or public repository.
Authorized integration security
Access to approved third-party platform integrations is restricted to authorized personnel. Credentials and tokens are not stored in the public website, and material business actions require human review.
Reporting a vulnerability
If you believe you have found a security vulnerability affecting dialpro-llc.com or a DialPro app, please report it to support@dialpro-llc.com. Please include:
- A description of the vulnerability and its potential impact
- Steps to reproduce it
- Any relevant URLs, screenshots, or logs
We ask that you avoid accessing or modifying data that does not belong to you, and that you give us a reasonable amount of time to investigate and address a report before disclosing it publicly. Our machine-readable disclosure contact is published at /.well-known/security.txt.
We do not currently operate a paid bug bounty program.