Allbirds Responsible Disclosure Program

Security is an essential part of maintaining trust in any modern digital business, and Allbirds recognizes the importance of continuously protecting its online platforms, systems, and information assets. As technology evolves and new threats emerge, maintaining a secure environment requires ongoing attention, collaboration, and improvement. Independent security researchers contribute valuable insights that can help identify potential weaknesses before they become larger issues. By encouraging responsible communication from the security community, Allbirds supports a proactive approach to strengthening its digital ecosystem.

The company welcomes reports from individuals who discover potential vulnerabilities affecting its websites, applications, services, or related technology resources. Responsible reporting helps ensure that security concerns can be investigated and resolved efficiently while minimizing risk to customers, employees, and business operations. Researchers who identify possible issues are encouraged to act in good faith and share their findings privately so that appropriate corrective actions can be taken.

The disclosure process is intended to support collaboration rather than exploitation. Security testing should be conducted carefully, with consideration for the stability and integrity of the systems involved. Researchers are expected to avoid actions that could disrupt services, interfere with normal business operations, or negatively impact users. Activities that place unnecessary strain on systems or compromise the availability of services are inconsistent with the goals of responsible vulnerability research.

While Allbirds appreciates the efforts of security researchers, participation in the disclosure process does not include financial rewards. The company does not operate a public vulnerability reward initiative and does not guarantee compensation for submitted reports. Contributions are made voluntarily, with the shared objective of improving overall security. Even without a reward structure, the company strives to engage constructively with individuals who provide legitimate and useful findings.

Protecting privacy remains a fundamental expectation throughout the reporting process. Researchers should avoid accessing information beyond what is necessary to confirm the existence of a vulnerability. If personal information, confidential records, or other sensitive data is encountered unintentionally, exposure should be kept to an absolute minimum. Such information should not be copied, stored, distributed, modified, or deleted under any circumstances. Immediate notification allows the company to evaluate the situation and take appropriate protective measures.

Another important principle of responsible disclosure is coordinated communication. Security issues should remain confidential while they are being reviewed and addressed. Allowing adequate time for investigation and remediation helps reduce the possibility of malicious exploitation before a solution is available. Premature public disclosure can increase risk and complicate response efforts, making cooperation between researchers and organizations particularly important.

Researchers are expected to comply with all applicable laws, regulations, and ethical standards while conducting their work. Testing activities should remain focused on identifying security concerns without attempting to gain unauthorized benefits or exploit discovered weaknesses. The purpose of disclosure is to improve security outcomes rather than to create risk, inconvenience, or harm for users or the organization.

When reports are submitted in accordance with responsible disclosure expectations, Allbirds seeks to review them promptly and fairly. The security team evaluates the information provided, determines whether the reported issue can be verified, and assesses its potential impact. If a vulnerability is confirmed, efforts are made to prioritize remediation based on severity and risk. Researchers may receive updates regarding the progress of the review process when appropriate, supporting open and professional communication.

Certain categories of testing fall outside the intended scope of responsible vulnerability reporting. Activities involving physical access attempts, impersonation, deceptive communications, phishing campaigns, service disruption testing, resource exhaustion attacks, or other forms of nontechnical intrusion are generally not considered acceptable under the disclosure framework. The focus remains on identifying legitimate technical vulnerabilities in a safe and responsible manner.

High-quality reports can significantly improve the efficiency of the review process. Detailed descriptions help security personnel understand the issue, reproduce the conditions under which it occurs, and determine the most effective remediation strategy. Information such as affected systems, observed behavior, reproduction steps, technical evidence, and supporting documentation can greatly assist in validating findings. Screenshots, logs, or other relevant materials may also help clarify complex issues when included appropriately.

Private communication remains the preferred method for reporting suspected vulnerabilities. Submissions that contain accurate, complete, and clearly organized information allow the security team to assess potential risks more effectively and implement solutions more quickly. Through cooperation between organizations and the broader security research community, digital environments can become more resilient, dependable, and secure.

By encouraging responsible reporting practices and maintaining an open channel for vulnerability disclosures, Allbirds reinforces its commitment to protecting users, safeguarding information, and continuously improving its security posture. This collaborative approach helps create a stronger foundation for trust while supporting safer online experiences for customers, partners, and employees alike.