Security

Security & Responsible Disclosure

We take the security of our website, apps and advertising API integrations seriously.

Website security

  • This website is served exclusively over HTTPS, with automatic redirection from HTTP.
  • We apply security-related HTTP response headers, including HSTS, a Content Security Policy, X-Content-Type-Options, a Referrer-Policy, a Permissions-Policy and frame protection.
  • No API credentials, developer tokens, or account secrets are stored in this website's front-end code or public repository.

Authorized integration security

Access to approved third-party platform integrations is restricted to authorized personnel. Credentials and tokens are not stored in the public website, and material business actions require human review.

Reporting a vulnerability

If you believe you have found a security vulnerability affecting dialpro-llc.com or a DialPro app, please report it to support@dialpro-llc.com. Please include:

  • A description of the vulnerability and its potential impact
  • Steps to reproduce it
  • Any relevant URLs, screenshots, or logs

We ask that you avoid accessing or modifying data that does not belong to you, and that you give us a reasonable amount of time to investigate and address a report before disclosing it publicly. Our machine-readable disclosure contact is published at /.well-known/security.txt.

We do not currently operate a paid bug bounty program.