Security and Vulnerability Disclosure Policy

How to report a security issue and what we ask from good-faith researchers.

Last updated August 7, 2026

1. Reporting a vulnerability

If you believe you found a vulnerability in a system operated by Dotless, email a private report to support@dotless.co with the subject “Security vulnerability report”. Include the affected URL or component, impact, reproducible steps, relevant request or response details with secrets removed, and a safe way to contact you. Do not include personal data or exploit data beyond what is necessary to explain the issue.

2. Good-faith research rules

Research is authorized under this Policy only when you:

test only Dotless-operated systems and accounts or data you own or have express permission to use;

use the minimum access needed to confirm the issue, stop if you encounter another person’s data, and report it without retaining or sharing it;

do not disrupt availability, degrade service, send spam, use social engineering, access physical facilities, introduce malware, create persistence, or damage or alter data;

do not evade rate limits through high-volume automation or test payment providers, vendors, customer-published sites, or other third-party systems without their permission; and

give Dotless a reasonable opportunity to investigate and remediate before any public disclosure and coordinate disclosure details with us.

3. Our commitment

We will review good-faith reports, may request clarification, and will keep the reporter informed when practicable. Dotless will not initiate legal action against a researcher for accidental, good-faith activity that complies with this Policy. If a third party initiates action, we may explain that the activity was conducted under this Policy. This commitment does not authorize unlawful conduct, bind third parties, waive rights for activity outside this Policy, or promise a reward.

4. Exclusions and rewards

This is a coordinated-disclosure channel, not a bug-bounty program. We do not promise payment. Reports limited to missing best-practice headers, self-XSS, clickjacking on pages with no sensitive action, automated scanner output without demonstrated impact, denial-of-service testing, or vulnerabilities solely in an unsupported browser may be closed without action. Dotless may change or end this Policy prospectively, but will assess already submitted good-faith research under the version in effect when reported.