Allbirds treats digital security as a continuous responsibility and an essential part of maintaining trust across its platforms. The company recognizes that protecting systems, infrastructure, and user data requires ongoing attention rather than one-time measures. Independent security researchers are considered an important part of this effort, as their external perspective can help uncover vulnerabilities that internal processes may not immediately detect. Because of this, Allbirds supports the careful reporting of potential security issues across its digital products and services.
Anyone who identifies a possible vulnerability is encouraged to communicate it directly to the company. The intention behind this process is to allow issues to be addressed efficiently and safely before they can be exploited. Reports should be shared in a responsible and constructive manner, with the focus placed on improving system resilience. Allbirds acknowledges the contribution of researchers who spend time examining its systems and views this collaboration as a valuable part of its overall security strategy.
It is important to note that there is no formal reward or incentive program associated with vulnerability reporting. Submissions are reviewed without any guarantee of payment or compensation. Participation is entirely voluntary and based on a shared goal of strengthening security protections. Even without financial rewards, Allbirds aims to maintain respectful communication with individuals who submit findings and to engage with them throughout the review process where appropriate.
Researchers are expected to conduct all testing activities in a way that avoids causing disruption or harm. Any actions that could negatively affect system availability, interfere with user experience, or compromise operational stability are not permitted. Testing should be carried out in a controlled and ethical manner, ensuring that no attempt is made to exploit system weaknesses for personal gain or to interfere with business operations.
Respect for privacy and data protection is a key requirement throughout the disclosure process. Any exposure to sensitive or personal information during testing must be limited strictly to what is necessary to identify and report the issue. Such data should never be stored, shared, or misused in any form. If private information is encountered unintentionally, it must be reported immediately so it can be handled appropriately by the security team.
Allbirds also requests that researchers avoid publicly disclosing vulnerabilities before the company has had sufficient time to investigate and implement a fix. Allowing a reasonable review period helps ensure that issues are resolved properly and reduces the risk of exploitation. Coordinated disclosure supports a safer environment for both users and systems.
In situations where researchers follow these guidelines, Allbirds commits to engaging in good faith and will not pursue legal action related to the reported security testing activities. However, this understanding applies only when the research is conducted within the defined boundaries and complies with applicable laws and ethical expectations.
Once a report is received, it is reviewed by the security team, which aims to acknowledge submissions in a timely manner. Valid issues are prioritized based on severity and impact, and efforts are made to address them as quickly as possible. Researchers may receive updates on the progress of verified issues, depending on relevance and resolution status.
Certain types of testing are excluded from the scope of this process, including physical intrusion attempts, social engineering techniques, phishing campaigns, denial-of-service actions, or any activity that intentionally disrupts service performance. These activities are not considered acceptable forms of vulnerability research within this framework.
To assist in the evaluation process, reports should be clear and detailed. Useful submissions typically include a description of the issue, affected components, steps to reproduce the behavior, and any supporting evidence. Clear documentation helps the security team understand and verify the problem more efficiently.
All suspected security issues should be submitted privately through the designated communication channel, typically email. By providing accurate and complete information, researchers enable faster assessment and resolution. Through this cooperative approach, Allbirds works alongside the security community to strengthen protections and ensure a safer digital environment for all users.