Reporting a security concern

Updated

If you’ve found a vulnerability, seen something you shouldn’t have access to, or suspect an account is compromised — we want to hear about it immediately, and you will never be penalized for a good-faith report.

How to report

Email [email protected]. That address goes to the people who handle security, not a general queue. If you receive no acknowledgment within one business day, escalate to the contact listed on our security page.

For issues tied to your own firm’s account (a suspicious sign-in, a phishing email targeting your staff), you can also submit a support request marked Data & security — it’s triaged with the same urgency.

What to include

  • What you saw, as specifically as you can describe it
  • Where and when — URLs, approximate times, which account was signed in
  • Screenshots if you have them
  • How to reach you for follow-up

What happens next

Security reports are acknowledged, investigated, and answered by a human. If your report affects your firm’s data, we’ll tell you what happened and what we did about it — not a form letter.

Please don’t

  • Don’t test a suspected vulnerability against other firms’ data — report it instead.
  • Don’t publish details before we’ve had a chance to fix the issue; we’ll work with you on responsible timing.
  • Don’t include client-confidential material in a report unless it’s necessary to describe the problem — describe around it where you can.

Not sure it’s “security”?

Report it anyway. “A client says they saw a document we didn’t share” and “I got a weird password-reset email” are both worth five minutes of our time, and the false alarms are genuinely fine.

Didn't find what you needed?

Send us a request — a person on our support team reads every one.

Contact support