Reporting a security incident

How to report a suspected security issue right away.

Reporting a security incident

If you think something is wrong with the security of your Sophie account, please report it right away. Fast reporting helps us protect you and everyone else on your team.

Email us immediately

Send an email to [email protected] as soon as you notice something off. Use this address for security concerns only — for general help, see Getting support.

What counts as a security incident

You don't need to be certain — when in doubt, report it. Examples include:

  • Suspected unauthorized access — you think someone may have accessed your account or a teammate's account without permission.
  • Lost or stolen device — a phone, laptop, or tablet you use to sign in to Sophie is lost or stolen.
  • Suspicious email — you receive a message claiming to be from Sophie that asks for your password or other sensitive information (phishing).
  • Unexpected changes — clients, settings, or conversations in your account changed and you didn't make the changes.
  • Shared credentials exposed — a password or sign-in link may have been shared or leaked.

What to include in your report

Tell us as much as you can. Helpful details include:

  • What happened, in your own words.
  • When it happened (date and approximate time, plus your time zone).
  • Your name, email, and the name of your firm.
  • The email address or account you think is affected.
  • Any screenshots, suspicious messages, or other details you can share.

What happens next

Our security team will review your report and reach out. We may ask follow-up questions, help you secure your account (for example, by resetting your password), and check whether anyone else may be affected.

While you wait

If your device was lost or stolen, or you think your password may be exposed:

  • Change your password from a device you trust, if you can.
  • Sign out of other sessions if Sophie shows that option under Settings.

These steps help protect your account while our team investigates.


Did this page help you?