Vulnerability disclosure policy
Last updated 24 August 2026
Vandorisk sells software that helps manufacturers run a coordinated vulnerability disclosure process. Not having one ourselves would be difficult to defend, so this is ours. It is also published in machine-readable form at /.well-known/security.txt.
How to report
Email hello@vandorisk.comwith “security” in the subject. Tell us what you found, where, and the steps to reproduce it. A short proof of concept helps more than a scanner export. If a report contains details you would rather not send in plain email, say so and we will arrange another channel before you send anything.
Please do not open a public issue or post the details before we have had a chance to fix them.
What to expect
- Acknowledgement within 72 hours, from a person, saying whether we have reproduced it yet.
- An assessment and a plan within 10 working days, including our view of the severity and whether we disagree with yours.
- Credit in the fix note if you want it, and no credit if you would rather not be named.
- We will tell you when it is fixed. We are a small team, so we will give you a real date rather than a target we cannot meet.
Safe harbour
If you make a good-faith effort to follow this policy, we will not pursue or support legal action against you for your research, and we will say so in writing if a third party asks. Good faith means: you stay within the scope below, you stop as soon as you have demonstrated the problem, you do not access, modify or retain other people’s data, and you give us a reasonable chance to fix it before telling anyone else.
If you are unsure whether something is in scope, ask first. We would rather answer a question than receive an apology.
In scope
The Vandorisk application at www.vandorisk.com, including its API, and this website.
Out of scope
- Anything that requires denial of service, brute force at volume, spam, social engineering, or physical access. Please do not test availability against production.
- Findings against our infrastructure providers rather than us. Report those to the provider.
- Missing hardening headers, cookie flags or TLS configuration with no demonstrated impact. Tell us anyway if you like, but they will be triaged as improvements rather than vulnerabilities.
- Accounts, products or assessments belonging to anyone other than you. Create your own account to test against.
We do not run a paid bug bounty. We will not pretend otherwise to attract reports.
For the controls behind the product, see Security.