Sluiten

Security Policy

Responsible Disclosure

At Dovendi, we take the security of our systems seriously. We value the efforts of security researchers who help us make our systems safer.

Scope

In Scope:

  • All domains and subdomains of dovendi.com

  • Our web applications and APIs

  • Security vulnerabilities that have a real impact on security

Out of Scope:

  • Social engineering attacks

  • Physical attacks

  • DoS/DDoS attacks

  • Spam or phishing attacks

  • Brute force attacks

  • Issues that only work on outdated browsers

  • Clickjacking on pages without sensitive actions

How to Report a Security Issue

Email: Send a detailed report to security@dovendi.com

Encryption: Preferably use our PGP key for sensitive information

Information

Include the following in your report:

  • Description of the security vulnerability

  • Steps to reproduce the issue

  • Potential impact

  • Screenshots or videos (if applicable)

What We Ask of You

  • No Harm: Do not perform actions that could cause damage

  • Privacy: Respect the privacy of other users

  • Confidentiality: Do not publicly share your findings before we have resolved the issue

  • One report per security issue

Our Process

  • Confirmation: We confirm receipt within 2 business days

  • Assessment: We assess the report within 5 business days

  • Updates: We keep you informed of our progress

  • Resolution: We work on a solution depending on the severity

  • Disclosure: After resolution, findings can be made public

Response Times

Critical: 24 hours response, solution within 7 days

High: 48 hours response, solution within 30 days

Medium: 5 business days response, solution within 90 days

Low: 10 business days response, solution within 180 days

Legal

By reporting a security vulnerability through this process:

  • We will not take legal action against you

  • We will work together on a responsible disclosure

  • We respect your privacy and will not share personal information without consent

Acknowledgement

We appreciate your commitment to keeping the internet safe. Eternal fame will be yours, and depending on your contribution, you will receive a delicious cake and, in any case, permission for an online reference wherever you desire.

Contact: security@dovendi.com

PGP Key: https://dovendi.com/pgp-key.asc

Last Updated: December 2025