Skip to content
use HEY with your business →

Security response

We appreciate your concern

Keeping customer data safe and secure is a huge responsibility and a top priority. We work hard to protect our customers from the latest threats. Your input and feedback on our security is always appreciated.

Reporting security problems

If you are a HEY customer and your account is under an attack such as hacking or mailbombing, send us an email at We will respond within two hours and work with you to counter the attack.

Report security vulnerabilities via our bug bounty program on HackerOne. We’ll review your report and get back to you as soon as we can, usually within 72 hours. Please email our Security team if you have questions about the bug bounty program or don’t hear back from us on HackerOne in a timely manner.

For other urgent or sensitive reports, please email our Security team. If you feel it necessary, use our public key to keep your message safe and please provide us with a secure way to respond. We’ll respond as soon as we can. Please follow up or ping us on Twitter if you don’t hear back.

For requests that aren’t urgent or sensitive: submit a support request.

Tracking and disclosing security issues

We work with security researchers to keep up with the state-of-the-art in web security. Have you discovered a web security flaw that might impact our products? Please let us know. If you submit a report, here’s what will happen:

Our products are built on the Ruby on Rails framework (which we created and maintain). The issue you reported might affect Rails, Ruby, or some other part of our technology stack. We ask for your patience while we also make sure other companies and their customers are protected. Either way, you’ll always have a 37signals contact for your issue.

Thanks for working with us

We respect the time and talent that drives new discoveries in web security technology. The following researchers and companies have gone out of their way to work with us to find, fix, and disclose security flaws safely:

Sorry, this website uses features that your browser doesn’t support. Upgrade to a newer version of Firefox, Chrome, Safari, or Edge and you’ll be all set.