Email: info@totesoft.com
Suggested initial-response target: acknowledge within three business days. This should be published as a target, not a guaranteed SLA, unless Totesoft approves a binding support commitment.
Do not send source numeric values unless support specifically requests them through an approved secure process. Never send credentials, tokens, or full issue exports.
Use the subject Espresso Security Report. Include affected version, concise reproduction steps, and impact. Do not publicly disclose an unresolved vulnerability or include live customer data.