Vulnerability Disclosure Policy
OfficeSpace's Vulnerability Disclosure Policy, updated February 23, 2026, outlines responsible reporting procedures for security vulnerabilities found in their public-facing web, mobile, and API products under specified domains, prohibits unauthorized testing activities such as scanning, DoS attacks, and social engineering, excludes internal and customer data systems from testing, and emphasizes responsible disclosure without a current bug bounty program.
Updated: February 23, 2026
At OfficeSpace, we take the security of our products very seriously. We educate our staff on security best practices and our development process includes quality assurance steps to ensure our products are of high quality and secure. However, like all complex software products, it is possible that a security vulnerability may be present in one of our products.
Should you find a potential vulnerability, please report the details to our security team at security@officespacesoftware.com. We appreciate responsible disclosure and will acknowledge security researchers when an issue has been reported, adhering to the following parameters.
OfficeSpace does not currently have a bug bounty program in place.
This policy outlines how to report vulnerabilities, what is in scope, and what researchers can expect from us in return.
Scope
This policy applies to:
- Public-facing systems operated by OfficeSpace Software under the *.officespacesoftware.com, *.greetly.com, and/or *.dojo.com domain.
- Web and mobile applications we develop and maintain.
- Public APIs and developer-facing tools under our control.
This policy does not grant permission to access or test:
- Production systems.
- Systems hosting customer data.
- Internal administration systems.
- Any infrastructure not publicly documented.
- Third-party services we rely on but not control.
Prohibited Activities (Without Prior Written Authorization)
The following activities are not permitted:
- Network or application scanning.
- Use of automated vulnerability scanners or fuzzers.
- Attempts to access, modify, or exfiltrate data.
- Denial-of-service (DoS), brute-force, or resource-exhaustion testing.
- Social engineering or phishing.
- Physical access attempts.
- Password spraying or credential stuffing.
- Exploiting vulnerabilities in third-party or dependent services.
If you are unsure whether a system or activity is in scope, please contact us before proceeding.
Out-of-Scope Findings
We do not consider the following to be valid or actionable security vulnerabilities for the purposes of this policy:
- Displayed server software banners or version information.
- Descriptive error messages (unless they reveal sensitive data).
- Missing HTTP security headers (e.g., X-Frame-Options, Content-Security-Policy).
- Missing or incorrect DNS SPF, DKIM, or DMARC records.
- CSRF vulnerabilities on forms accessible to anonymous users.
- Username or email enumeration.
- Disclosure of known public files (e.g., /robots.txt, /humans.txt).
- Clickjacking on pages with no sensitive actions.
- Rate-limiting issues without demonstrated impact.
What You Can Report
We welcome reports based on:
- Passive observation.
- Interactions with our services as an authorized user.
- Reviews of publicly available code, documentation, or resources.
- Disclosure of vulnerabilities discovered elsewhere that also affect our systems.
If you’ve identified a potential vulnerability that falls outside of active testing, we encourage you to report it. If you’re unsure whether something qualifies, just ask.
How to Report a Vulnerability
Please send an email to:
security@officespacesoftware.com
Include the following:
- A clear description of the suspected vulnerability.
- Steps to reproduce (if applicable).
- Affected domain, URL, or system.
- Any tools or payloads used (optional).
- Your contact details or alias (optional).
We appreciate well-written, actionable reports.
Safe Harbor
If you:
- Act in good faith.
- Follow this policy.
- Avoid unauthorized testing
Then OfficeSpace Software:
- Will not pursue legal action against you under applicable laws (including CFAA).
- Will not pursue contractual or DMCA claims.
- Will consider your testing authorized under applicable laws.
- Will work with you to understand and remediate any concerns.
This safe harbor only applies to activities conducted within the scope of this policy and in a non-malicious, good-faith manner.
What You Can Expect
We will:
- Acknowledge receipt of your report within 3 business days.
- Investigate and validate the reported issue.
- Keep you reasonably informed during the process.
- Notify you when remediation is complete.
We aim to resolve valid vulnerabilities within 90 days of confirmation, though complex fixes may require more time. We will coordinate with you on disclosure timing.
No Rewards or Bounties
OfficeSpace Software does not currently offer monetary rewards, gifts, or other compensation for vulnerability disclosures. This policy exists to support collaboration and transparency in securing our services.
We may publicly acknowledge significant contributions — with your consent. Anonymous submissions are also accepted.
Disclosure Guidelines
Please refrain from publicly disclosing a vulnerability until:
- We have confirmed this issue; and
- Remediation has been deployed, or
- Both parties have mutually agreed on disclosure timing.
Related Information
- Security Overview: https://officespacesoftware.com/security
- Privacy Policy: https://officespacesoftware.com/privacy
- Policies: https://trust.officespacesoftware.com/
Contact: security@officespacesoftware.com
Preferred-Languages: English
Thank you for helping us maintain a secure and resilient platform.
Last Updated: December 2025
Related
Accessibility Policy
OfficeSpace is committed to making its software accessible to all users, including those with disabilities, by striving to comply with WCAG 2.1 Level AA standards, incorporating inclusive design, addressing user feedback, and implementing specific improvements such as proper labeling, color contrast adjustments, form labels, and structured navigation, while actively working toward full accessibility and inviting user input to guide ongoing enhancements.
Privacy Policy
OfficeSpace Software Inc.'s updated Privacy Policy (as of March 4, 2026) explains that by using their website or services and submitting personal information such as name, email, and company details, users consent to data collection and usage for improving site performance, research, marketing, and communication, with data securely stored and retained until deletion is requested, while also noting that the policy may be updated periodically and questions can be directed via email.
Third Party App Terms of Use
The Third Party App Terms of Use specify that users must have legal authority to bind their employer or entity to the terms, use the Service primarily for workplace management, may optionally connect to third-party applications without OfficeSpace's warranty or support, and must provide and maintain accurate registration information to access the Service.
Customer Support Policy
The Customer Support Policy outlines the Subscription Services Agreement between OfficeSpace Software Inc. and the Customer, detailing the provision and use of workplace management software, ownership and handling of Customer Data, responsibilities regarding contractor access and data security, compliance requirements, restrictions on storing personal data without a Data Processing Addendum, and OfficeSpace's rights to update and modify the Service features.
Client Privacy Policy
The Client Privacy Policy of OfficeSpace Software Inc. details how it collects, uses, and protects personal data from clients who use its Subscription Services, specifying that OfficeSpace collects necessary contact information and client-uploaded data to provide services per client instructions, processes additional data from client communications for service support and administration, gathers technical data from devices for optimization, and commits to processing client data solely to fulfill contracted services under strict data protection obligations.
Workplace Experience Software for Hybrid Employees
OfficeSpace is a workplace experience software designed to enhance hybrid employees' office days by enabling easy desk and room booking, automatic check-ins, live presence tracking, seamless integration with tools like Slack and Teams, real-time office wayfinding, targeted announcements, and streamlined facilities requests, all deployable within 35 days to improve team connection, space utilization, and workplace navigation.