[ Security ]

Responsible Disclosure

Last updated: July 19, 2026

We take the security of Headways and our customers seriously. If you believe you have found a security vulnerability in any Headways product or service, we want to hear from you and will work with you to resolve it quickly.

Reporting a vulnerability

Please email a detailed report to support@headways.ai. Include the steps to reproduce the issue, the affected URL or component, and any supporting material (proof-of-concept, screenshots, or logs) that helps us understand the impact. We will acknowledge your report and keep you informed as we investigate.

Scope

This policy covers the systems we operate, including:

  • headways.ai — our marketing site
  • docs.headways.ai — our documentation site
  • The Headways platform and application products

Guidelines for good-faith research

  • Give us a reasonable opportunity to investigate and remediate before disclosing an issue publicly or to any third party.
  • Only interact with accounts you own or have explicit permission to test. Do not access, modify, or delete other users’ data.
  • Avoid privacy violations, data destruction, and any degradation of our services. Do not run denial-of-service tests, automated high-volume scanning, spam, or social-engineering attacks against our staff or users.
  • Do not use or exploit a vulnerability beyond what is necessary to confirm it.

Safe harbor

We will not pursue or support legal action against researchers who report vulnerabilities in good faith and in accordance with this policy. If legal action is initiated by a third party against you for activity that complied with this policy, we will make it known that your actions were authorized.

Rewards

We do not currently offer a paid bug-bounty program. We are grateful for every good-faith report and will happily acknowledge researchers who help us keep Headways secure.

For more about our security practices, see our Trust & Security page.