Trust center
Reporting a vulnerability
If you have found a security issue in an EveryBill system, tell us directly before telling anyone else. We investigate every good-faith report.
How to reach us
Email info@everybill.com with a description of the issue, the steps to reproduce it, and any supporting evidence (screenshots, request/response logs, or a proof-of-concept). Do not include real customer data in your report; use test data or redact it.
We will acknowledge a good-faith report within 3 business days and give you a status update at least every 10 business days until it is resolved.
Safe harbor
We will not pursue legal action against you for security research conducted in good faith, in scope, and consistent with this policy. This includes accessing or storing the minimum data necessary to demonstrate the issue, and stopping testing once you have established that a vulnerability exists rather than continuing to exploit it. If a third party initiates legal action related to research covered by this policy, we will make clear that your activity was authorized.
Scope
In scope
- The EveryBill consumer payment portal and self-pay websites
- Authentication, session handling, and access control issues
- Server-side vulnerabilities (injection, SSRF, broken access control, and similar)
- Misconfigurations in publicly reachable EveryBill infrastructure
Out of scope
- Social engineering, phishing, or physical attacks against staff or facilities
- Denial-of-service testing of any kind
- Automated vulnerability scanning at volume without prior arrangement
- Issues in third-party services we integrate with but do not operate
- Reports based on out-of-date browsers or missing best-practice headers with no demonstrated impact