Vulnerability Disclosure Policy
Last updated: June 2026
We welcome good-faith security research. If you believe you have found a vulnerability in Doctorine, tell us — we will work with you to verify, fix, and credit it.
How to report
-
Email security@doctorine.xyz
with a description, reproduction steps, and impact. Machine-readable
details:
/.well-known/security.txt(RFC 9116). - Include enough detail to reproduce. A working proof of concept against your own test workspace is ideal.
Our commitment (triage SLA)
- Acknowledgement within 2 business days.
- Triage decision within 5 business days.
- We keep you informed through remediation and credit you on request once a fix ships.
Scope
In scope:
- The Doctorine platform: the dashboard, the public API, the CLI surfaces.
- Customer documentation portals served by Doctorine, including assisted-beta custom-domain deployments.
- This website and our published SDK/client artifacts.
Out of scope:
- Denial-of-service, volumetric, or rate-limit exhaustion testing.
- Social engineering, phishing, or physical attacks against staff or customers.
- Third-party subprocessor infrastructure (report to the vendor; see subprocessors).
- Findings requiring a stolen device, a compromised account, or man-in-the-middle positioning.
Safe harbor
We will not pursue or support legal action against researchers who: act in good faith within this scope, avoid privacy violations and data destruction, do not access data beyond what is necessary to demonstrate the issue, use only their own test accounts/workspaces, and give us reasonable time to remediate before public disclosure. Good-faith research conducted under this policy is considered authorized under applicable anti-hacking and anti-circumvention laws.
Rules of engagement
- Never access, modify, or exfiltrate another tenant's data. If a cross-tenant proof is unavoidable, stop at the first byte of evidence and report immediately.
- No automated scanning at a volume that degrades service.
- Do not publicly disclose before remediation is deployed (we target 90 days, faster for critical issues).