Third Party Index

Snapshot 17468

Document
Security advisories
URL
https://diligencevdr.ai/security/
Fetched
HTTP status
200
Content type
text/html; charset=utf-8
Fetch mode
static
Size
81105 bytes
SHA-256 (raw)
d67d44c010214c78b8350ff5daa653559d1e8ebc7beadbe8e0fe8ef5eb18c33a
SHA-256 (normalized text)
47b1708dfcff8ac73a4d9235a34b706c162d29fee39920748c453b0a9a2b15bd

Normalized text

Scripts and page chrome removed; this is what change detection compares.

On this page
Security & Vulnerability Disclosure
Last Updated: April 19, 2026
DiligenceVDR appreciates the security researchers who help keep our platform and our customers' data safe. This page describes how to report a vulnerability, what is in scope, and the safe harbor we offer for good-faith research.
How to report
Email [email protected] with a description of the issue, reproduction steps, and any proof-of-concept. We acknowledge reports within 2 business days.
Scope
In scope
diligencevdr.ai and all subdomains (including app.diligencevdr.ai)
The DiligenceVDR web application and public APIs
Out of scope
Third-party subprocessors (Cloudflare, Railway, WorkOS, Stripe, etc.) — please report those directly to the vendor
Denial-of-service, volumetric, or rate-limit testing
Social engineering of staff, customers, or vendors
Physical attacks against offices or data centers
Automated scanner output without a working proof-of-concept
Missing security headers, SPF/DMARC nits, or cookie flags without demonstrated impact
Safe harbor
We will not pursue legal action against researchers who:
Act in good faith and stay within the scope above
Do not access, modify, or exfiltrate customer data beyond the minimum needed to demonstrate the issue
Give us reasonable time to remediate before public disclosure (typically 90 days)
Do not violate applicable law
What we offer
We publicly acknowledge researchers who report valid issues, with permission. We do not currently run a paid bug-bounty program.