• Skip to main content
  • Skip to navigation
  • Skip to footer
  • Keyboard shortcuts
Get started, it's free!
  • Hire

    • Hiring

    • Document Storage

    • Onboarding

    Train

    • AI Course Builder

    • Microlearning

    • Distribution & Tracking

    Schedule

    • Scheduling

    • Time Clocking

    • Labor Compliance

    Pay

    • Payroll

    • Tip Management

    • On-Demand Pay

    Retain

    • Team Performance

    • Team Communications

    • Manager Log Book

    Manage your team's journey in one place

    Hire
    Find and onboard new hires faster.
    Train
    Build consistent skills across roles.
    Schedule
    Create smart, compliant schedules.
    Pay
    Turn time and tips into accurate pay.
    Retain
    Keep great people longer.
    • Hiring→
    • Document Storage→
    • Onboarding→
    • AI Course Builder→
    • Microlearning→
    • Distribution & Tracking→
    • Scheduling→
    • Time Clocking→
    • Labor Compliance→
    • Payroll→
    • Tip Management→
    • On-Demand Pay→
    • Team Performance→
    • Team Communications→
    • Manager Log Book→
  • Pricing
  • Built for

      Bakeries

      Bars & Breweries

      Cafes & Coffee Shops

      Catering

      Juice Bars

      Pizzerias

      Pubs

      Full Service

      Quick Service

      Franchises

  • Integrations
  • Resources

    • Templates icon

      Templates and Tools

      Downloadable and interactive tools to help run your restaurant efficiently

    • Food Runner

      Food Runner

      Sign up for our monthly (unboring) newsletter

    • Restaurant data

      Restaurant Data

      Facts and figures on industry standards

    • customers

      Customer Stories

      Get to know the restaurants we work with

    • Podcast

      Podcast

      Restaurant management tips from industry insiders

    • blog

      Blog

      Read about trends, challenges and solutions

    • support

      Support

      Your knowledge base for everything 7shifts

    • Academy

      Academy

      Gain certification with our free online courses

    Featured Reads

    • Customer Feature

      See the Restaurant Innovators 2025

      Read more

    • Case Study

      Mandy's Salads Success Story

      Read more

    • Case Study

      How Little Italy Ristorante Turned Hours of Payroll Processing into Minutes

      Read more

  • Get started, it's free!Login

Hire

  • Hiring

  • Document Storage

  • Onboarding

Train

  • AI Course Builder

  • Microlearning

  • Distribution & Tracking

Schedule

  • Scheduling

  • Time Clocking

  • Labor Compliance

Pay

  • Payroll

  • Tip Management

  • On-Demand Pay

Retain

  • Team Performance

  • Team Communications

  • Manager Log Book

Manage your team's journey in one place

Hire
Find and onboard new hires faster.
Train
Build consistent skills across roles.
Schedule
Create smart, compliant schedules.
Pay
Turn time and tips into accurate pay.
Retain
Keep great people longer.
  • Hiring→
  • Document Storage→
  • Onboarding→
  • AI Course Builder→
  • Microlearning→
  • Distribution & Tracking→
  • Scheduling→
  • Time Clocking→
  • Labor Compliance→
  • Payroll→
  • Tip Management→
  • On-Demand Pay→
  • Team Performance→
  • Team Communications→
  • Manager Log Book→

Built for

    Bakeries

    Bars & Breweries

    Cafes & Coffee Shops

    Catering

    Juice Bars

    Pizzerias

    Pubs

    Full Service

    Quick Service

    Franchises

Resources

  • Templates icon

    Templates and Tools

    Downloadable and interactive tools to help run your restaurant efficiently

  • Food Runner

    Food Runner

    Sign up for our monthly (unboring) newsletter

  • Restaurant data

    Restaurant Data

    Facts and figures on industry standards

  • customers

    Customer Stories

    Get to know the restaurants we work with

  • Podcast

    Podcast

    Restaurant management tips from industry insiders

  • blog

    Blog

    Read about trends, challenges and solutions

  • support

    Support

    Your knowledge base for everything 7shifts

  • Academy

    Academy

    Gain certification with our free online courses

Featured Reads

  • Customer Feature

    See the Restaurant Innovators 2025

    Read more

  • Case Study

    Mandy's Salads Success Story

    Read more

  • Case Study

    How Little Italy Ristorante Turned Hours of Payroll Processing into Minutes

    Read more

Keyboard shortcuts

ActionShortcut
Open cheatsheetShift+?
Go to Homeg h
Go to Productg p
Go to Pricingg m
Go to Built Forg b
Go to Integrationsg i
Go to Resourcesg r

Responsible Disclosure

Last updated: Oct 23nd, 2025

Our Commitment to Security

At 7shifts, the security of our systems and the protection of our customer data is a top priority. We value the crucial role the security research community plays in helping us stay secure. This policy explains how to report vulnerabilities to us, what you can expect from us, and how we can work together to protect our users.

Our Responsible Disclosure Program is facilitated through Inspectiv, a private bug bounty platform.

How to Report a Vulnerability

We have two distinct channels for submitting your findings. Please choose the one that best fits your situation.

  1. For Bug Bounties (Seeking Compensation): If you are seeking a monetary reward for your findings, you must be a registered researcher with Inspectiv.`
    1. To Submit: Register and submit your findings through the official 7shifts Bug Bounty Program on Inspectiv.
    2. Sign up here: https://www.inspectiv.com/researchers
  2. For Voluntary Disclosure (Not Seeking Compensation): If you are not seeking compensation but wish to report a vulnerability for the good of the community, please use our voluntary disclosure form.
    1. Submit here: https://client.inspectiv.com/vdp/7shifts/submit-report

Scope

This policy applies to any digital assets owned, operated, or maintained by 7shifts. To help you focus your efforts, we have defined what is in and out of scope.

In-Scope Assets

  1. Mobile Applications
    1. 7shifts Android App
    2. 7shifts iOS App
  2. API Endpoints
    1. https://login.7shifts.com/oauth2
    2. https://files.7shifts.com
    3. https://gql.7shifts.com
    4. https://app.7shifts.com/gql/v2
  3. Web Portal
    1. https://app.7shifts.com

Out-of-Scope Assets & Activities

  1. Any domains, subdomains, or services not explicitly listed in the “In-Scope” section.
  2. Third-party services or vendors used by 7shifts.
  3. Social engineering (e.g., phishing), physical attacks, or testing that targets our employees, offices, or data centers.
  4. Activities that could disrupt our service (Denial of Service, spamming, etc.).

Excluded Vulnerability Types

We generally do not award bounties for vulnerabilities that have no demonstrable security impact. While we encourage you to report anything you find, the following are examples of issues that are not eligible for a reward through our bug bounty program:

  1. Reports from automated scanners without a validated proof-of-concept.
  2. Missing security best practices (e.g., missing HTTP security headers, SPF/DKIM records, weak SSL cipher suites) without proof of a real-world vulnerability.
  3. Disclosure of known-public files or software versions.
  4. Clickjacking on pages without sensitive actions.
  5. Username/email enumeration.
  6. Self-XSS and other issues requiring unlikely user interaction.

For a complete and detailed list of excluded vulnerability types, please review the full program policy on the Inspectiv platform.

Program Rules & Expectations

To ensure our program is safe and effective for everyone, we require all researchers to adhere to the following rules:

  1. Report promptly: Let us know as soon as you discover a potential vulnerability.
  2. Avoid harm: Do not disrupt our systems, destroy data, or violate the privacy of our users. If you encounter any user data (PII, PHI, etc.), stop immediately and report it.
  3. Test responsibly: Only interact with test accounts you own. Do not perform testing that violates laws or compromises data that is not your own.
  4. Maintain confidentiality: Provide us a reasonable amount of time (at least 180 days) to resolve an issue before you disclose it publicly. Do not discuss vulnerabilities through unofficial channels.
  5. No extortion: Do not engage in any form of extortion or threats.

Security researchers that are participating in our bug bounty program, which is managed by Inspectiv, will be required to agree to Inspectiv’s rules, terms, and conditions. Sign up at https://www.inspectiv.com/researchers.

Safe Harbor

We consider security research conducted under this policy to be authorized. We will not initiate or support legal action against you for good-faith, accidental violations of this policy, provided you comply with all applicable laws and adhere to the guidelines outlined herein.

Our Process & Timelines

Once you submit a report, here’s what you can expect from us:

  1. Initial Response: We will do our best to reply to your initial report within 48 hours.
  2. Updates: We will provide updates on our progress at reasonable intervals.
  3. Public Disclosure: We ask for at least 180 days to remediate a vulnerability before public disclosure. We will coordinate with you to ensure our public disclosures are posted at the same time.

Rewards

Monetary bounties are available for valid, in-scope vulnerabilities submitted through our official bug bounty program which is managed by Inspectiv. Payouts are based on the severity of the vulnerability and the criticality of the affected asset.

Note: The “Tiers” below correspond to the criticality of the asset you are testing. A detailed overview of which assets fall into which tier is available on the Inspectiv platform. See https://www.inspectiv.com/researchers.

Severity Tier 1 Tier 2 Tier 3
Critical $500 $1,000 $2,500
High $250 $500 $1,000
Medium $100 $250 $500
Low $50 $100 $200

Severity is determined by Inspectiv’s triage team based on impact and the privileges required to exploit the vulnerability. For more detail on the rating process, please refer to the documentation within the Inspectiv platform.

Frequently Asked Questions (FAQ)

What information should I include in my report?
Please include a clear description of the vulnerability, steps to reproduce it, potential impact, and any proof-of-concept code or screenshots that demonstrate the issue.

How long will it take to resolve my report?
Our goal is to acknowledge your report within 48 hours. Remediation timelines vary depending on the severity and complexity of the vulnerability, but we aim for resolution within our 180-day public disclosure window.

Can I publicize my findings?
We request that you allow us at least 180 days to remediate the vulnerability before public disclosure.

How long does it take to receive a bounty payment?
Once the issue is validated and resolved, Inspectiv processes payouts according to their standard schedule.

Restaurant Scheduling
and Payroll Platform

7shifts

Products

  • Restaurant Scheduling
  • Mobile Scheduling
  • Team Communication
  • Manager Log Book
  • Time Clocking
  • Team Engagement
  • Task Management
  • Labor Compliance
  • Operations Overview
  • Document Storage
  • Performance Management
  • Employee Onboarding
  • Hiring
  • Payroll
  • Tip Management
  • Tip Pooling

Company

  • About Us
  • Customers
  • Compare
  • Careers
  • Become A Partner
  • Affiliates
  • Media Kit
  • Legal
  • Pricing
  • Sitemap
  • Contact Sales

Resources

  • Blog
  • Resource Center
  • Restaurant Guides
  • Restaurant Data
  • Restaurant Podcast
  • Academy
  • Templates
  • Labor Savings
  • Integrations
  • Labor Cost Calculator
  • ROI Calculator

Built For

  • Quick Service
  • Full Service
  • Cafes & Coffee Shops
  • Bars & Breweries
  • Pizzerias
  • Juice Bars
  • Pubs
  • Bakeries
  • Catering
  • Franchises

Support

  • Help Center
  • Partner API
  • Contact Customer Support

Customer Stories

  • Jamba Juice
  • gusto!
  • Chatime
  • Mandy's
  • Little Italy Ristorante
  • Andolini's

Customer Stories

  • Jamba Juice
  • gusto!
  • Chatime
  • Mandy's
  • Little Italy Ristorante
  • Andolini's
Download on the App StoreGet it on Google Play

Ask AI for a summary of 7shifts

ChatGPTClaudePerplexityGeminiGrok
  • Facebook
  • X
  • Instagram
  • Linkedin
  • Spotify
  • Youtube

7shifts © 2026

  • Ai Info
  • Responsible Disclosure
  • Terms of Use
  • Terms of Service
  • Privacy Policy
  • California Privacy Policy Information
  • Your Privacy Choices