Success Layer / Partner Success Pulse
Last Updated: September 8, 2026
Success Layer welcomes good-faith reports of suspected security vulnerabilities in the systems listed below. This policy explains what is in scope, the rules that apply to testing, how to report, and what you can expect from us.
If you follow this policy, we will treat your research as authorized under it. Please read Section 10 for the limits of that authorization.
The following are out of scope unless Success Layer gives prior written authorization:
Third-party providers are out of scope. Success Layer uses third-party providers to operate its systems. Nothing in this policy authorizes you to test, probe, or attack a provider's systems — including Vercel, Neon, Resend, Sentry, Cal.com, Microsoft, or Namecheap — merely because Success Layer uses them. Those providers have their own policies, and only they can authorize testing of their systems.
Use only accounts and data you own or are expressly authorized to use. The App is invite-only. Use only accounts for which Success Layer or an applicable customer has expressly authorized testing; ordinary access to an account does not by itself grant permission to test with it. Do not create, obtain, or access additional accounts through unauthorized means.
Use the minimum activity necessary to demonstrate an issue, stop as soon as you have demonstrated it, and report it to us.
Partner Success Pulse is a multi-tenant SaaS product. If you suspect an authorization or tenant-isolation issue, do not use the suspected issue to browse, enumerate, copy, or retrieve another customer's information. Demonstrate the issue using your own accounts, harmless identifiers, or the smallest non-sensitive proof possible, then stop and report it.
If you unexpectedly access another tenant's data or other information you are not authorized to see, stop immediately, do not retain or share it, and tell us what happened.
Partner Success Pulse is not intended to hold protected health information or patient information. Do not intentionally seek, access, transmit, copy, include, or retain PHI or patient information during testing or in a report.
If such information appears unexpectedly, stop, do not retain or share it, and report only the minimum security details we need to understand and fix the issue.
The following are not authorized under this policy:
Send reports to security@getsuccesslayer.com. Anonymous reports are accepted — we do not require your real name, a phone number, or government identification.
A useful report generally includes:
Please do not include unnecessary Customer Data, PHI, patient information, credentials, tokens, or secrets in a report. Describe what you found rather than sending the underlying data.
We ask that you give us a reasonable opportunity to investigate and remediate before disclosing an issue publicly, and that you coordinate timing with us.
We will acknowledge and review your report as reasonably practicable, triage it, ask you for more detail where we need it, validate the issue, and remediate as appropriate. We will try to keep you reasonably updated where that is practical.
We do not commit to a fixed acknowledgment or remediation timeframe.
Success Layer will treat the report and reporter information as confidential to the extent reasonably possible, subject to legal obligations and the need to investigate, remediate, or coordinate with relevant service providers.
Research conducted strictly within this policy's scope and conditions is authorized by Success Layer to the extent it can grant that authorization. Success Layer will not initiate or knowingly support legal action solely for that authorized research. We also will not initiate or knowingly support legal action solely for accidental, good-faith violations of this policy that do not cause harm, are promptly reported, and stop when discovered. This limited nonpursuit commitment does not expand the permitted testing scope.
This policy does not authorize:
Success Layer cannot authorize activity on behalf of another provider or person. If your research would affect a third party's systems, you need that party's authorization, not ours.
Success Layer does not currently operate a public paid bug-bounty program. No payment, swag, hall of fame, or public recognition is promised. Any recognition or reward is entirely discretionary unless separately agreed in writing.
The following are generally not treated as actionable standing alone unless a meaningful security impact or exploit chain is demonstrated:
None of these is inherently incapable of being a vulnerability. If you can show real impact, tell us and we will look at it.
Security reports may contain contact information, IP addresses, technical identifiers, browser and device details, timestamps, and other information needed to investigate the issue. Success Layer handles that information according to its Privacy Policy and uses it for security investigation, remediation, and related communications.
Do not include unnecessary Customer Data, PHI, patient information, credentials, secrets, or personal information in a report.
Our Security page describes how Partner Success Pulse handles account-level operational information, tenant isolation, role boundaries, and what we do not claim.
Customer-facing security and incident obligations are set by the applicable signed customer agreement, Order Form, and Data Processing Addendum. This policy does not create, replace, or vary those obligations, or override customer-specific restrictions in a signed agreement.
This policy does not expand Success Layer's rights to use Customer Data.
Research conducted strictly within the scope and conditions of this policy is authorized under it. Success Layer's general website and Service testing restrictions do not prohibit that authorized research.
For purposes of any Success Layer term requiring prior written authorization and an agreed testing scope for security testing, this published Vulnerability Disclosure Policy constitutes Success Layer's written authorization and defines the permitted testing scope only for research conducted strictly in accordance with this policy. This policy does not authorize testing outside the systems, methods, or conditions expressly permitted here.
Sasa Ilic d/b/a Success Layer
Nassau County, New York, USA
Security: security@getsuccesslayer.com
Legal: legal@getsuccesslayer.com
Privacy: privacy@getsuccesslayer.com