Responsible Disclosure
Last updated: July 19, 2026
We take the security of Headways and our customers seriously. If you believe you have found a security vulnerability in any Headways product or service, we want to hear from you and will work with you to resolve it quickly.
Reporting a vulnerability
Please email a detailed report to support@headways.ai. Include the steps to reproduce the issue, the affected URL or component, and any supporting material (proof-of-concept, screenshots, or logs) that helps us understand the impact. We will acknowledge your report and keep you informed as we investigate.
Scope
This policy covers the systems we operate, including:
- headways.ai — our marketing site
- docs.headways.ai — our documentation site
- The Headways platform and application products
Guidelines for good-faith research
- Give us a reasonable opportunity to investigate and remediate before disclosing an issue publicly or to any third party.
- Only interact with accounts you own or have explicit permission to test. Do not access, modify, or delete other users’ data.
- Avoid privacy violations, data destruction, and any degradation of our services. Do not run denial-of-service tests, automated high-volume scanning, spam, or social-engineering attacks against our staff or users.
- Do not use or exploit a vulnerability beyond what is necessary to confirm it.
Safe harbor
We will not pursue or support legal action against researchers who report vulnerabilities in good faith and in accordance with this policy. If legal action is initiated by a third party against you for activity that complied with this policy, we will make it known that your actions were authorized.
Rewards
We do not currently offer a paid bug-bounty program. We are grateful for every good-faith report and will happily acknowledge researchers who help us keep Headways secure.
For more about our security practices, see our Trust & Security page.