Skip to main content
Operator: San Gregorio Labs Inc.
Email: hello@tryswell.co
Address: 185 Wythe Ave f2, Brooklyn, NY 11249

What to email us about

Reporting a vulnerability

Email hello@tryswell.co with:
  • Description of the issue and its potential impact
  • Steps to reproduce, or a proof of concept (if applicable)
  • Affected component (Mac app, api.tryswell.co, or coach.tryswell.co) and app/build version
  • Your contact information
We aim to acknowledge reports within 3 business days and will work with you to validate, remediate, and let you know when a fix has shipped. Please coordinate with us before any public disclosure. We do not currently run a paid bug bounty program.

Safe harbor

We will not pursue legal action against, or support law-enforcement action against, security researchers who discover and report vulnerabilities in good faith under this policy, and who do not access, modify, or exfiltrate customer data beyond what is necessary to demonstrate the issue.

Scope

This policy covers the Swell Disco macOS application and Swell’s first-party backend (api.tryswell.co, coach.tryswell.co, and related storage). For vulnerabilities in third-party subprocessors, report to us so we can coordinate with the vendor; remediation is ultimately handled by that vendor. See our Subprocessor list.