> ## Documentation Index
> Fetch the complete documentation index at: https://security.tryswell.co/llms.txt
> Use this file to discover all available pages before exploring further.

# Contact

> Security, privacy, and vulnerability contact details and response SLAs for Swell.

**Operator:** San Gregorio Labs Inc.\
**Email:** [hello@tryswell.co](mailto:hello@tryswell.co)\
**Address:** 2 Wall Place Suite C, San Francisco, CA 94109

## What to email us about

| Topic                                                          | Email                                         | Target response                                                                                    |
| -------------------------------------------------------------- | --------------------------------------------- | -------------------------------------------------------------------------------------------------- |
| Security review / design partnership IT questions              | [hello@tryswell.co](mailto:hello@tryswell.co) | 2 business days                                                                                    |
| Vulnerability reports                                          | [hello@tryswell.co](mailto:hello@tryswell.co) | Acknowledge within 3 business days                                                                 |
| Privacy, access, or account deletion requests                  | [hello@tryswell.co](mailto:hello@tryswell.co) | 30 days                                                                                            |
| Security incident notification (confirmed unauthorized access) | [hello@tryswell.co](mailto:hello@tryswell.co) | Within 72 hours of confirmation (see [Privacy Policy §5](/privacy#security-incident-notification)) |
| DPA or security questionnaire                                  | [hello@tryswell.co](mailto:hello@tryswell.co) | 2 business days                                                                                    |

## Reporting a vulnerability

Email [hello@tryswell.co](mailto:hello@tryswell.co) with:

* Description of the issue
* Steps to reproduce (if applicable)
* Your contact information

Please do not publicly disclose unresolved vulnerabilities without coordinating with us. We do not currently run a paid bug bounty program.

See also the coordinated disclosure policy in our GitHub [`SECURITY.md`](https://github.com/Swell-App/swell-disco/blob/dev/SECURITY.md).

## Related documents

* [Security Overview](/)
* [Privacy Policy](/privacy)
* [IT Network Requirements](/network)
