Allbirds is committed to maintaining a secure digital environment and protecting the information shared by customers, employees, and business partners. The company understands that cybersecurity requires continuous attention and improvement, especially as technology changes and new risks develop. Security researchers and members of the broader technology community can provide valuable assistance by identifying potential weaknesses and helping organizations strengthen their systems. Through responsible security reporting, Allbirds encourages collaboration with individuals who discover possible vulnerabilities and works toward creating safer digital experiences for everyone.
The company welcomes reports from researchers who identify security concerns involving Allbirds websites, applications, services, or other technical resources. Responsible disclosure allows potential issues to be reviewed, investigated, and addressed before they can create broader risks. Researchers who submit reports are encouraged to act carefully, responsibly, and with the intention of improving security protections rather than exploiting weaknesses. By sharing information directly with the company, researchers help support stronger protection measures and contribute to the ongoing reliability of Allbirds digital platforms.
Allbirds accepts vulnerability reports as part of its commitment to security improvement, but the company does not operate a formal bug bounty program or provide guaranteed payments for submitted findings. Individuals who participate in the disclosure process should understand that financial rewards, gifts, or other forms of compensation are not promised. Instead, the process is based on cooperation, communication, and a shared interest in improving technology security. Allbirds appreciates the efforts of researchers who dedicate time and expertise to identifying potential issues and aims to maintain respectful communication throughout the review process.
When conducting security research, individuals are expected to follow responsible testing practices. Activities should be performed in a way that avoids disruption, damage, or negative effects on Allbirds systems, services, customers, or employees. Researchers should not attempt to interrupt website availability, interfere with normal operations, access systems beyond what is necessary to confirm a vulnerability, or perform actions that could create unnecessary risks. Security testing should also comply with all applicable legal requirements and should respect the rights and privacy of others.
Protecting confidential information is an essential part of responsible security research. If a researcher unintentionally encounters customer information, employee information, internal data, or other sensitive materials, that information should not be copied, stored, shared, modified, or used for any purpose beyond confirming and reporting the security issue. Researchers should limit access to only what is necessary and notify Allbirds promptly if sensitive information is discovered. Proper handling of information helps reduce potential harm and supports a secure resolution process.
Researchers are encouraged to provide Allbirds with sufficient time to investigate and resolve reported vulnerabilities before sharing details publicly or with outside parties. Allowing time for assessment and remediation helps the company understand the impact of an issue, develop appropriate solutions, and protect users from possible exploitation. Coordinated communication between researchers and the security team supports a more effective response and improves overall security outcomes.
Allbirds is committed to responding fairly to researchers who follow responsible disclosure principles. When reports are submitted in good faith and activities remain within appropriate boundaries, the company intends to work cooperatively and avoid unnecessary legal action related to legitimate security research. However, actions that involve harmful behavior, unauthorized misuse, or violations of applicable laws may fall outside the protections of the disclosure process.
After receiving a security report, Allbirds reviews the information carefully to determine whether the issue is valid, understand the potential impact, and identify appropriate corrective measures. The security team works to acknowledge submissions and provide updates when possible during the evaluation process. Confirmed vulnerabilities are addressed through reasonable steps designed to strengthen systems and reduce future risks.
Certain testing methods are not considered appropriate for responsible security reporting. These may include social engineering activities, phishing attempts, physical security testing, denial-of-service attacks, excessive resource consumption, or other methods that could negatively affect users or infrastructure. Reports involving these types of activities may not be handled through the standard vulnerability disclosure process.
To help the security team evaluate reported concerns effectively, researchers should provide detailed and accurate information whenever possible. A useful report may include a clear explanation of the suspected vulnerability, affected systems or features, testing methods used, steps required to reproduce the issue, and supporting evidence such as screenshots or technical details. Complete information allows the company to investigate more efficiently and determine the best way to address the concern.
Security reports should be submitted through private communication channels designated by Allbirds. By encouraging responsible reporting and maintaining open collaboration with security researchers, Allbirds continues to improve its technology protections and strengthen trust among everyone who interacts with its digital services. This cooperative approach supports a safer online environment while helping ensure that security remains an ongoing priority throughout the company’s operations.