Report a vulnerability
Last updated July 7, 2026
We take the security of MeetCrew seriously and welcome reports from security researchers. If you believe you have found a vulnerability in MeetCrew, this page tells you how to report it and what to expect.
How to report
Email security@meetcrew.ai with a clear description of the issue, the steps to reproduce it, the affected component or URL, and any proof-of-concept or supporting detail. If your report contains sensitive information, ask us for an encryption key and we will provide one.
Scope
In scope: the MeetCrew service, the admin application at admin.meetcrew.ai, and the marketing site at meetcrew.ai. Out of scope: third-party services we build on (for example Microsoft Azure, Microsoft Teams, Zoom, Webex, and Google Meet), findings that require physical access to a user's device, social-engineering or phishing of MeetCrew staff or customers, volumetric denial-of-service, and reports based solely on automated-scanner output without a demonstrated impact. Report issues in third-party services to that provider.
Safe harbor
We will not pursue or support legal action against researchers who act in good faith and follow this policy. To stay within it, do not access, modify, or delete data that is not yours; do not degrade or disrupt the Service; use only test accounts and data you control; stop as soon as you have demonstrated a vulnerability; and do not exfiltrate any data. Give us a reasonable opportunity to remediate before disclosing publicly.
What to expect
We aim to acknowledge a valid report within a few business days, keep you updated as we investigate, and let you know when the issue is resolved. We are grateful for responsible disclosure and are happy to credit reporters who wish to be recognized. We do not currently run a paid bug-bounty program, but that may change as we grow.
Coordinated disclosure
Please keep the details of any vulnerability confidential until we have had a reasonable chance to address it, and coordinate any public disclosure with us. Our security posture and how the product is built are described on our Trust & Security page, and summarized in our security overview (PDF).