Responsible Disclosure
Help us keep America’s Call Center and our customers safe. We appreciate the work of the security research community.
Introduction
America’s Call Center (ACC), a Porch Group company, values the work of security researchers in helping keep our systems and our customers’ data safe. If you believe you’ve found a security vulnerability in ACC’s systems, we want to hear from you.
Contact
When submitting a report, please include:
- A clear description of the vulnerability and its potential impact
- Step-by-step reproduction instructions
- Supporting materials (screenshots, proof-of-concept code, logs)
- The affected URL, endpoint, or system component
What to expect
We will acknowledge your report within 2 weeks. Our security team will assess severity and impact as part of ACC’s vulnerability management process, and may follow up for a retest once resolved.
Out of scope
Theoretical attacks without real-world impact, optional hardening recommendations, and disruptive testing such as denial-of-service attacks.
Safe harbor
ACC will not pursue civil or criminal action against researchers who make a good-faith effort to comply with this policy, provided testing is limited to accounts or systems you own or have explicit permission to test.
ACC does not currently offer monetary rewards, but valid reports may be credited in our Hall of Fame (with your permission).
Hall of Fame
No entries yet