Security and Responsible Disclosure

Last updated · Circo, Inc.

In plain English

  • Found a vulnerability? Email security@capable.so. We reply within one business day.
  • Test only against accounts you own, never touch other people’s data, and give us time to fix the issue before you publish.
  • If you follow these rules, we will not take legal action against you, and we will credit you if you want.
  • We tell affected customers about a personal data breach within 72 hours.

This summary helps you read the document. The numbered sections below are what bind.

Contents

1. Our commitment

Companies trust Capable with the record of who owns them. We welcome reports from security researchers and treat every credible report seriously. This policy explains how to report a vulnerability and what you can expect from Circo, Inc., which operates Capable. For how we protect data day to day, see our Security page and the security measures in our DPA.

2. How to report

Email security@capable.so. Please include:

  • the affected URL, endpoint, or feature;
  • a description of the issue and its potential impact;
  • step-by-step instructions or a proof of concept that lets us reproduce it; and
  • how you would like to be credited, if at all.

Please do not put vulnerability details in support tickets, public forums, or social media.

3. Scope

In scope: capable.so and its subdomains, the Capable web application and stakeholder portal, our APIs, the MCP connector endpoint and its OAuth flow, and the open-source Capable engine we publish.

Out of scope:

  • services run by third parties, such as Vercel, Stripe, Google, Resend, or Railway; please report those to the provider;
  • denial-of-service or load testing;
  • social engineering, phishing, or physical attacks against our staff, offices, or customers;
  • reports from automated scanners without a demonstrated impact;
  • missing security headers, cookie flags, or email authentication records without a practical exploit;
  • clickjacking on pages with no sensitive actions; and
  • vulnerabilities that require a compromised device or an outdated, unsupported browser.

4. Rules for good-faith research

  • Test only with accounts and companies you create yourself. A free trial workspace is fine.
  • Do not access, change, or delete data that belongs to anyone else. If you reach other people’s data by accident, stop, do not keep a copy, and tell us right away.
  • Use the smallest proof of concept needed to show the issue. Do not pivot to other systems or keep access after you confirm a finding.
  • Do not degrade the service for other users, and do not send spam through invitations or email features.
  • Do not demand payment in exchange for withholding a report.
  • Keep the details confidential until we have fixed the issue, or until 90 days after your report, whichever comes first, unless we agree on a different date together.

5. What you can expect from us

  • We acknowledge your report within one business day.
  • We tell you our assessment of severity within five business days.
  • We keep you updated while we fix the issue and tell you when it is resolved.
  • With your permission, we credit you publicly once the fix is live.

6. Safe harbor

If you make a good-faith effort to follow this policy, we consider your research authorized. We will not bring legal action against you, or support action by others, under anti-hacking laws such as the Computer Fraud and Abuse Act, under anti-circumvention laws, or under our Terms of Service, for that research.

If a third party brings legal action against you for research that followed this policy, we will make it known that your work was authorized by us. This safe harbor does not cover research that breaks the rules above or the law.

7. Rewards

We do not run a paid bug bounty program at this time. We may, at our discretion, thank researchers for significant findings. Any reward is a goodwill gesture, not a contract.

8. Security incidents affecting customers

If a security incident leads to unauthorized access to customer personal data, we notify affected customers without undue delay and within 72 hours of becoming aware, as our Data Processing Addendum requires. The notice explains what happened, what data was involved, and what we are doing about it. Customers can report suspected account compromise to security@capable.so at any time.