- Your app’s client secret or one of its access tokens has leaked.
- You notice unusual API activity from your app.
- You find a vulnerability in Attio.
Helping us understand the issue
The more context you share, the faster the Attio team can act. Where possible, include:- Your app ID - This is the same as your ‘Client ID’, which you can find in the OAuth section of your app in the Developer console.
- What happened - What leaked or what you found, and how.
- When it happened - When the issue started, or when you first noticed it.
- What you’ve already done - For example, whether you’ve rotated your client secret or revoked any access tokens.