Vulnerability Disclosure Program

Delivering fast, stable and secure services has always been a top priority at noCRM. We greatly appreciate feedback and bug reports. If you believe you have found a bug, a security or privacy vulnerability on our products, please report it to us.

How to report

All reports must be sent to our support team at support@youdontneedacrm.com

Your report must provide evidence and all required information to reproduce the issue, please include:

How we handle these reports

Each report will be escalated to be analyzed by our engineering team.

If you are a customer of noCRM, you will always get an answer from us:

If you are not a customer of noCRM and the issue can't be reproduced or you did not provide evidence, we won't answer your email.

Once the issue is identified:

  1. We analyse the impacts of the issue and we investigate its potential past occurrences in our logs or on our database.
  2. We write automated tests to reproduce the issue and to avoid further occurences (if applicable).
  3. We fix the issue.
  4. The fix is reviewed by at least one other member of the engineering team.
  5. Once the fix is approved, we release it.
  6. If the update concerns the mobile version of noCRM (Android or iOS), all users will be prompted to update their app to the new version. For the web version of noCRM, a simple page reload is enough.

Once the issue is fixed:

  1. We answer you and any other person who has reported it
  2. We communicate to other users who have been impacted by the issue

Vulnerability disclosure policy

Please abide by these guidelines:

  • Do not communicate any issue or vulnerability, even resolved ones, to the public or to any third parties, unless approved by noCRM.
  • Do not discuss vulnerabilites outside of the Program. To avoid badly intentioned people to harm our services and customers, don't report issues on social media, use our email.

Following actions are strictly forbidden:

  • DDoS (Denial of Service) attacks on our services.
  • Social engineering of noCRM employees or contractors.
  • Compromise of noCRM users or employees account.