Responsible disclosure

Report security issues safely.

Give researchers and customers a clear route to report vulnerabilities without posting details publicly.

Secure applicant linkGuided verificationControlled evidencePass / Refer / Fail
Report safely

Give researchers and customers a private route to report issues.

Security reports are handled privately, and live applicant testing requires permission.

Include

Affected page or endpoint, steps to reproduce, screenshots and impact.

Avoid

Reports exclude access to, copying, changing, deleting or disclosing other people's data.

Response approach

DoorID is designed to acknowledge, triage and resolve reports responsibly.

Exact timings are formalised in the production security policy and customer agreements.

Acknowledge

Confirm receipt and ask for any missing detail.

Triage

Assess severity, affected customers and containment steps.

Close

Confirm remediation or explain why the issue is not accepted.

Next step

See DoorID on a real workflow.

Talk to us and we will map DoorID to your application process, risk team and approval workflow.