Security Researchers
We believe in working with the security community. The people listed below have responsibly disclosed vulnerabilities and helped make ContractRev safer for everyone.
Syed Khurram Shoaib
Reported and helped fix the following:
- Session invalidation on logout
- URL injection in signup email
- Session persistence after password reset
- DMARC policy enforcement
- Password length DoS hardening
Report a Vulnerability
If you find a security issue in ContractRev, we want to hear from you. Please email us with the details — include steps to reproduce, the impact, and any relevant screenshots or proof-of-concept material.
We ask that you give us a reasonable amount of time to investigate and address the issue before disclosing it publicly. We do not pursue legal action against researchers who act in good faith and follow responsible disclosure practices.
support@contractrev.comReady to Review Your Contract?
Upload your contract and get an AI-powered risk analysis in under 30 seconds. 3 free credits — no sign-up required.