Performance Intelligence

Security

Last updated: July 14, 2026

Reporting a vulnerability

If you believe you've found a security vulnerability in Performance Intelligence, we want to know. Please report it privately by email rather than filing a public issue or posting about it — that gives us a chance to fix it before it's exploited.

What's in scope

In scope — the Performance Intelligenceweb application and its API: authentication and session handling, access control between companies and roles, the AI assistant's data boundaries, and standard web vulnerability classes (injection, XSS, CSRF, SSRF, and similar).

Out of scope — volumetric load or denial-of-service testing against our infrastructure. It doesn't tell us anything we can't already see from our hosting provider, and it degrades the service for real companies using it. Social engineering, physical access attempts, and testing against accounts or data that aren't your own are also out of scope.

How to report

Email [email protected] with a description of the issue, the steps to reproduce it, and its potential impact. Include enough detail for us to reproduce the problem — proof-of-concept requests or screenshots are welcome. Please avoid accessing, modifying, or exfiltrating data that isn't yours beyond what's needed to demonstrate the issue.

What to expect

We'll acknowledge your report within 5 business days and let you know if we need more information. We investigate every good-faith report and will follow up once it's resolved. We won't pursue legal action against research conducted in good faith, within the scope above, that doesn't harm users or degrade the service.

A note on rewards

We don't currently run a paid bug-bounty program. We're grateful for responsible reports and will credit researchers who ask to be credited once a fix ships.