Skip to main content
Doctorine
Menu

Vulnerability Disclosure Policy

Last updated: June 2026

We welcome good-faith security research. If you believe you have found a vulnerability in Doctorine, tell us — we will work with you to verify, fix, and credit it.

How to report

Our commitment (triage SLA)

Scope

In scope:

Out of scope:

Safe harbor

We will not pursue or support legal action against researchers who: act in good faith within this scope, avoid privacy violations and data destruction, do not access data beyond what is necessary to demonstrate the issue, use only their own test accounts/workspaces, and give us reasonable time to remediate before public disclosure. Good-faith research conducted under this policy is considered authorized under applicable anti-hacking and anti-circumvention laws.

Rules of engagement