Skip to content

Security at Succeedium

At Succeedium, we take the security and privacy of our clients seriously. Our products, including the TeamOne Google Sheets™ add-on and SPACE for IBM Planning Analytics, are trusted by enterprise organizations and built with security as a core principle.

We are committed to maintaining high security standards through:

  • Continuous SOC 2 Type II auditing
  • Annual third-party penetration testing
  • Ongoing internal threat modeling and secure development practices

Live control statuses, audit reports, and policy documentation are available at our trust center:
https://trust.succeedium.com/

Report a Security Issue

If you believe you’ve found a security vulnerability in any Succeedium product or service, please report it promptly through our secure form:

📄 Succeedium Security Incident Report Form

We appreciate responsible disclosures and will investigate all submissions quickly. You can also contact us at: security@succeedium.com

Bug Bounty Program

We welcome independent security researchers to responsibly test and report vulnerabilities in our public services.

Scope

  • In Scope:

    • The TeamOne Google Sheets™ Add-on
    • The SPACE Chrome Extension
    • Any Succeedium-hosted public APIs
    • Extensions under *.succeedium.com
  • Out of Scope:

    • Denial-of-service (DoS) or brute-force attacks
    • Physical access or social engineering
    • Internal-only services or accounts
    • Testing that violates user privacy or service availability

Bounty Rewards

We provide discretionary rewards based on severity, reproducibility, and real-world impact:

SeverityExample FindingsReward (CAD)
HighStored XSS, Privilege Escalation$250 – $500
MediumIDOR, CSRF, Reflected XSS$100 – $250
LowInfo Disclosure, Open Redirects$50 – $100

Please note: not all reports qualify for a reward. We appreciate all good-faith efforts to help us improve security.


Responsible Disclosure

We support responsible security research and commit to:

  • Responding to valid reports within 2 business days
  • Coordinating fix timelines and acknowledgments
  • Never pursuing legal action against good-faith researchers

Thank you for helping us make Succeedium products safer for everyone.