Security & Responsible Disclosure Policy
We welcome good-faith reports that help us fix real security issues. This Policy defines the current scope and the conduct expected when testing or reporting a vulnerability.
> OPERATOR / #DOBRO, LLC
> JURISDICTION / UNITED STATES
> BASE / NEBRASKA
> STATUS / PUBLIC
How to report
Submit a security report through the Legal / Privacy Request form and select “Security vulnerability.” Include the affected URL or component, reproduction steps, impact, evidence necessary to understand the issue, and a reliable way to contact you. Do not include unnecessary personal data, credentials, or data belonging to other users.
Good-faith research
We consider research good faith when it is designed to identify and report a vulnerability, uses the minimum access necessary to demonstrate impact, avoids harm and disruption, protects information encountered during testing, and gives us a reasonable opportunity to investigate before public disclosure.
Out-of-scope and prohibited activity
- denial-of-service, resource exhaustion, destructive testing, or traffic flooding;
- social engineering, phishing, credential theft, or impersonation;
- physical attacks, attempts to access offices, devices, networks, or personnel;
- accessing, altering, retaining, or disclosing data that is not yours beyond the minimum proof necessary;
- automated high-volume scanning that materially degrades service;
- extortion, threats, coercive disclosure, or demands for payment as a condition of non-disclosure;
- testing third-party systems without the third party’s authorization; or
- violating law or causing avoidable harm to people, property, or systems.
Our response
We will make reasonable efforts to acknowledge credible reports, investigate them based on severity and available evidence, and remediate verified vulnerabilities according to risk. We do not promise a particular response or remediation time through this public policy.
No automatic bounty or compensation
This Policy is not a bug-bounty program and does not promise payment, employment, contracting, public credit, or any other reward. Any compensation or recognition must be agreed by #Dobro in writing.
No blanket authorization
This Policy does not authorize conduct that is unlawful, destructive, outside the stated scope, or prohibited by a third party. If a proposed test could materially affect availability, expose another person’s data, or require access beyond ordinary public functionality, request written authorization before testing.