Vulnerability Disclosure Policy
Effective date: 1 August 2026 · Last updated: 21 July 2026
Actionable.co Canada Inc. (“Actionable”) values the security research community and welcomes reports of security vulnerabilities in our platform and services. This policy explains how to report a vulnerability to us, what is in scope, and what you can expect in return.
1. Our commitment
If you make a good-faith effort to comply with this policy during your research, we will consider your activity authorized, work with you to understand and resolve the issue quickly, and not pursue or support legal action against you for accidental, good-faith violations.
2. Scope
The following are in scope:
-
the Actionable Habit Builder (subdomains of actionable.co)
-
Actionable Insights (actionable-insights.co and subdomains)
-
the Actionable REST API and Model Context Protocol (MCP) server;
-
actionable.co and knowledge.actionable.co
The following are out of scope:
-
third-party services and sub-processors we use (report those to the relevant provider);
-
denial-of-service (DoS/DDoS) and volumetric testing;
-
social engineering, phishing, or physical attacks against Actionable staff, partners, clients, or facilities;
-
findings from automated scanners without a demonstrated, exploitable impact.
In addition, the following are generally not eligible on their own unless you can demonstrate a concrete, exploitable security impact:
-
missing or “misconfigured” security headers (for example Content-Security-Policy, HSTS, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy);
-
missing cookie flags (Secure, HttpOnly, SameSite) on non-sensitive cookies;
-
banner, version, or software-fingerprint disclosure, and verbose error messages or stack traces that contain no sensitive data;
-
missing or weak email-authentication records (SPF, DKIM, DMARC);
-
TLS/SSL configuration observations such as weak ciphers or BEAST/POODLE without a working exploit;
-
clickjacking on pages with no sensitive, state-changing action;
-
self-XSS, or issues that require the victim to paste content or that affect only the reporter;
-
CSRF on unauthenticated actions or low-risk forms (for example logout);
-
open redirects without a demonstrated security impact;
-
absence of rate limiting or brute-force protection without a demonstrated impact;
-
host-header injection, or content/text injection, without a working exploit;
-
disclosure of public or non-sensitive files (for example robots.txt), and autocomplete or EXIF-metadata observations;
-
vulnerabilities affecting only unsupported or end-of-life browsers, platforms, or plugins;
-
reports that are purely best-practice recommendations with no security impact.
3. How to report
Send reports to security@actionable.co
This email address, along with our PGP key, can be found in our RFC 9118 security.txt file at https://start.actionable.co/.well-known/security.txt
In your report, please include:
-
a clear description of the vulnerability and its potential impact;
-
step-by-step instructions to reproduce it, including affected URLs or endpoints;
-
any proof-of-concept code, screenshots, or logs; and
-
how you would like to be credited (optional).
Encrypt sensitive details where possible and do not include real personal data of others in your report.
4. Rules for researchers
-
Only test accounts and data that belong to you, or that you have explicit permission to test.
-
Do not access, modify, delete, or exfiltrate data that is not yours, and stop as soon as you confirm a vulnerability.
-
Do not degrade, disrupt, or overload our services.
-
Do not use the vulnerability beyond the minimum needed to demonstrate the issue.
-
Give us a reasonable opportunity to remediate before disclosing publicly, and coordinate any public disclosure with us.
5. What to expect from us
-
We aim to acknowledge your report within 3 business days.
-
We will provide an initial assessment and keep you updated on remediation progress.
-
We will let you know when the issue is resolved, and credit you if you wish.
6. Recognition
Actionable does not currently operate a paid bug-bounty program. We are grateful for responsible disclosures and are happy to acknowledge researchers who help keep our platform secure.
7. Contact
Security reports: security@actionable.co.
For privacy matters, contact our Privacy Officer at privacy@actionable.co.
For more information about our privacy and security practices visit our Trust Center.

