Skip to content
NoShow AI

Security

Security

How we protect your account and your clients’ information, and how to tell us about a problem.

Last updated

Report a vulnerability

Email hello@noshow247.com with "Security" in the subject. Tell us what you found, the steps to reproduce it, and the impact you expect. The same contact is published in /.well-known/security.txt.

  • Only test against your own account. Don't access other customers' data.
  • Don't send texts to phone numbers you don't own, and don't run load or denial-of-service tests.
  • Give us reasonable time to fix the issue before sharing it publicly.

We'll confirm we received your report, keep you updated while we fix it, and credit you if you'd like. We don't offer paid bounties at this time.

How we protect data

  • All traffic uses HTTPS with HSTS. Pages send a strict Content-Security-Policy and can't be framed by other sites.
  • Passwords are stored only as bcrypt hashes. Google sign-in is also available.
  • Google Calendar access is read-only, and its tokens are encrypted at rest with AES-256-GCM. Disconnecting the calendar revokes our access and deletes the tokens.
  • Our staff accounts use two-factor authentication (required for administrators). Support staff view a customer's account only with that customer's permission, for a limited time, and every view is logged.
  • Application data is hosted in the United States (US West, Oregon). Payments are handled by Paddle.com; we never see or store card numbers.
  • Deleting your account in Settings permanently deletes your business, clients, appointments, and messages.

More detail is in the privacy policy. Healthcare practices that need a Business Associate Agreement should email us before starting.