Snapshot 17468
Normalized text
Scripts and page chrome removed; this is what change detection compares.
On this page Security & Vulnerability Disclosure Last Updated: April 19, 2026 DiligenceVDR appreciates the security researchers who help keep our platform and our customers' data safe. This page describes how to report a vulnerability, what is in scope, and the safe harbor we offer for good-faith research. How to report Email [email protected] with a description of the issue, reproduction steps, and any proof-of-concept. We acknowledge reports within 2 business days. Scope In scope diligencevdr.ai and all subdomains (including app.diligencevdr.ai) The DiligenceVDR web application and public APIs Out of scope Third-party subprocessors (Cloudflare, Railway, WorkOS, Stripe, etc.) — please report those directly to the vendor Denial-of-service, volumetric, or rate-limit testing Social engineering of staff, customers, or vendors Physical attacks against offices or data centers Automated scanner output without a working proof-of-concept Missing security headers, SPF/DMARC nits, or cookie flags without demonstrated impact Safe harbor We will not pursue legal action against researchers who: Act in good faith and stay within the scope above Do not access, modify, or exfiltrate customer data beyond the minimum needed to demonstrate the issue Give us reasonable time to remediate before public disclosure (typically 90 days) Do not violate applicable law What we offer We publicly acknowledge researchers who report valid issues, with permission. We do not currently run a paid bug-bounty program.