Security

Report a Security Issue

Found a vulnerability on sosne.com? We take platform and customer data security seriously — here's how to report it responsibly.

Last Updated: July 2026

If you have discovered a security vulnerability on sosne.com, we encourage you to report it to us immediately. Sonse LLC takes the security of our platform and our customers' data very seriously. We review all legitimate reports and aim to resolve confirmed issues as quickly as possible. Please read this page carefully before submitting a report.

Fundamentals

If you follow the principles below when reporting a security issue to sosne.com, Sonse LLC will not initiate legal action or enforcement investigations against you in response to your report.

We ask that you:

  1. Give us reasonable time to review and fix the issue before disclosing it publicly or sharing it with others.
  2. Do not interact with or access private accounts without the account owner's explicit consent.
  3. Make a good-faith effort to avoid privacy violations, service disruptions, or data destruction.
  4. Do not exploit the vulnerability for any reason, including to demonstrate further risks or access sensitive data.
  5. Comply with all applicable local, state, and federal laws and regulations.

Responsible Disclosure Program

Sonse LLC recognizes security researchers who help protect our platform by responsibly reporting vulnerabilities. We do not currently offer monetary bounties, but every valid report is reviewed, acknowledged, and credited at our discretion.

To have your report reviewed, you must:

  1. Follow all fundamentals listed above.
  2. Report a valid security vulnerability that poses a genuine risk to user privacy or platform security.
  3. Submit your report directly to contact@sosne.com — please do not contact employees directly.
  4. Disclose any accidental privacy violations or service disruptions that occurred during your research.
  5. Understand that response priority is based on risk severity and may take some time.

How We Prioritize Reports

Please provide detailed and reproducible steps in your report — issues that cannot be reproduced may take longer to validate. We assess and prioritize reports based on the following severity levels:

Critical Severity

  • Remote Code Execution
  • Remote Shell or Command Execution
  • Vertical Authentication Bypass
  • SQL Injection leaking customer data
  • Full account takeover

High Severity

  • Lateral authentication bypass
  • Disclosure of sensitive internal data
  • Stored XSS affecting other users
  • Local file inclusion
  • Insecure handling of authentication cookies

Medium Severity

  • Logic or business process flaws
  • Insecure direct object references
  • CSRF on sensitive actions
  • Unvalidated redirects to external sites

Low Severity

  • Open redirects
  • Reflected XSS
  • Low-sensitivity information leaks
  • Missing security headers

Non-Reportable Issues

The following are generally out of scope for review:

  • Denial of Service (DoS/DDoS) attacks or testing
  • Spam or social engineering attacks
  • Physical security issues
  • Vulnerabilities in third-party services or plugins not directly controlled by Sonse LLC
  • Reports generated solely by automated scanning tools without manual validation
  • Issues already known to our team or previously reported

How to Submit a Report

To report a security vulnerability, please send an email to contact@sosne.com with the subject line: "Security Vulnerability Report – sosne.com".

Your report should include:

  • A clear description of the vulnerability
  • Step-by-step instructions to reproduce the issue
  • The potential impact of the vulnerability
  • Any screenshots, videos, or proof-of-concept code (if applicable)

We will acknowledge your report within 3 business days and keep you informed of our progress throughout the resolution process.

Contact Us

Address
26412 Old Hwy 20, Madison, AL 35756, USA
Business Hours (CST / UTC−6)
Mon–Sat 9:00 AM – 5:00 PM Sunday Closed