PlusTeams
Terms of Use Privacy Policy Cookie Policy Security

Security Policy

Momentum Dashboard Corp. ("Momentum") welcomes reports of security vulnerabilities. This is our coordinated vulnerability disclosure policy: how to reach us, what we will do with your report, and the protections that apply to you when you report in good faith.

Reporting a vulnerability

Email security@momentumdash.com, our single point of contact for security reports. The same address is published in machine-readable form at /.well-known/security.txt. For anything that isn’t a security issue, please use help@momentumdash.com instead.

Please tell us where the issue is, what an attacker could do with it, and how to reproduce it. A proof of concept helps. Let us know if you plan to disclose publicly, and how you would like to be credited. Please report to us before sharing the issue anywhere else.

This policy covers Momentum’s products and services generally: our extension and apps on every platform we publish to, including unlisted and beta builds, along with momentumdash.com and its subdomains. If you aren’t sure whether something we run is covered, assume we want to hear about it and tell us. Current versions are in scope. A fix ships as a new release; updating to it is how earlier versions get fixed.

Please don’t do any of this, even to demonstrate an issue: denial of service or load testing, social engineering or phishing aimed at our staff, customers or vendors, or physical attacks. Testing of that kind sits outside this policy and its protections.

A few kinds of report are out of scope, and won’t get the acknowledgment below:

  • Platforms we don’t run. Our help site is hosted by Zendesk and payments are processed by Stripe, so those go to their security teams. We do want to hear about our own configuration or content on those platforms, but we can’t authorize testing on someone else’s service.
  • Scanner output with no demonstrated impact: missing hardening headers, cookie flags, TLS preferences, version banners, self-XSS.
  • A known CVE in a dependency with no demonstrated path to exploiting it in what we ship. We patch dependencies as a matter of course; a report is actionable only if the issue is actually reachable.

What to expect from us

We will acknowledge a report that is in scope under this policy within 10 business days; if you haven’t heard from us by then, please send it again.

We will assess what you send us, tell you what we intend to do, and let you know when a fix ships. We prioritize security fixes by severity and will ship a hotfix where the issue warrants it. Every store reviews updates before they reach users, and those review times are not ours to control, so we can’t promise a date on a store’s behalf. Where we can, we will describe a mitigation you can apply in the meantime.

We may decline to engage with reports that are automated, duplicative, or made in bad faith, and with anyone who is abusive toward our staff. This has no bearing on the safe harbor below, which stands for any research carried out in good faith.

Safe harbor

If you make a good-faith effort to comply with this policy, we will consider your research authorized, we will not pursue or recommend legal action against you in connection with it, and if a third party brings action we will make it known that your research was authorized.

That authorization extends to our Terms of Use: where the two conflict, including over their restrictions on reverse engineering, this policy governs the research it covers, and we won’t suspend or close your account for it.

Good faith means you test only against accounts and data that you own or are authorized to use; you do not access, modify, delete or retain anyone else’s data; you do not degrade the service for other people; you use only the access needed to demonstrate the issue and do not keep it; and you comply with applicable law. If you encounter another person’s data, stop, don’t save a copy, and tell us what you saw and how you reached it.

This policy states how Momentum will respond, and cannot bind third parties. If you’re unsure whether a test is in bounds, ask us before you run it.

Disclosure and recognition

Please give us 90 days from acknowledgment before disclosing an unresolved issue publicly. If the fix ships sooner, we are happy to disclose sooner. If a fix is still reaching users when the 90 days are up, we may ask you to wait a little longer; we will tell you why and give you a date. We publish an advisory for the vulnerabilities we fix, once the update is available, at Security Advisories.

We don’t run a paid bug bounty and can’t offer monetary rewards, but we are glad to credit you in the advisory. Tell us the name and link to use, or ask to stay anonymous.

For the products with digital elements we make available in the EU, Momentum is the manufacturer under Regulation (EU) 2024/2847, the Cyber Resilience Act. Where a vulnerability in those products is actively exploited, or an incident meets the regulation’s severity threshold, we report it to the relevant European authorities, and we tell affected users what happened and what they can do to protect themselves. Reporting something to us places none of these obligations on you.

Changes to this policy

We review this policy after any significant security event and as our products change.

Last updated August 31, 2026.

Momentum

Plus For Teams Download Release Notes

Connect

Join a Workshop Blog Contact Careers Partner with Us

Support

Help Center Account Gift Plus

Follow Us

Instagram
Facebook
X
Privacy & Legal