Security Researchers

We believe in working with the security community. The people listed below have responsibly disclosed vulnerabilities and helped make ContractRev safer for everyone.

Syed Khurram Shoaib

Reported and helped fix the following:

  • Session invalidation on logout
  • URL injection in signup email
  • Session persistence after password reset
  • DMARC policy enforcement
  • Password length DoS hardening

Report a Vulnerability

If you find a security issue in ContractRev, we want to hear from you. Please email us with the details — include steps to reproduce, the impact, and any relevant screenshots or proof-of-concept material.

We ask that you give us a reasonable amount of time to investigate and address the issue before disclosing it publicly. We do not pursue legal action against researchers who act in good faith and follow responsible disclosure practices.

support@contractrev.com

Ready to Review Your Contract?

Upload your contract and get an AI-powered risk analysis in under 30 seconds. 3 free credits — no sign-up required.

From YOUR SideTrack-Changes DOCXNegotiation Talking PointsFree · 3 Credits · 30s