Security practice

Responsible Disclosure

If you have found a security vulnerability in a Technical Dost system, we want to hear about it. This policy sets out what is in scope, how to reach us, what we commit to in return, and the protections that apply to good-faith research.

How to report

Machine-readable
/.well-known/security.txt (RFC 9116)
First response
Within 72 hours

Please include enough detail to reproduce the issue: the affected URL or endpoint, the steps taken, and what you observed. A short proof of concept helps considerably. Please do not include third-party personal data.

Scope

In scope

  • technicaldost.com and its subdomains
  • The Technical Dost web application and its public API

Out of scope

  • Findings from automated scanners with no demonstrated impact
  • Missing security headers with no demonstrated exploit path
  • Social engineering of staff, customers, or vendors
  • Physical attacks against offices or personnel
  • Denial-of-service testing of any kind
  • Reports against third-party services we consume but do not operate

What we commit to

Acknowledge within 72 hours

We confirm receipt and tell you who is handling the report.

Keep you updated

We share our assessment of severity and our remediation plan, and tell you when the fix ships.

Coordinated disclosure within 90 days

We aim to remediate and publish within 90 days of your report. If we need longer, we will say why and agree an extension with you rather than letting the deadline pass silently.

Credit where you want it

We will name you in the disclosure if you would like to be named, and will respect a request to stay anonymous.

No legal action for good-faith research

See safe harbour below.

Safe harbour

We will not pursue or support legal action against you for security research conducted in good faith under this policy, provided that you:

  • stay within the in-scope systems listed above;
  • stop as soon as you have demonstrated the issue, and do not access, modify, or download data belonging to anyone other than yourself;
  • do not degrade, disrupt, or deny service to our systems or our users;
  • give us a reasonable opportunity to remediate before disclosing publicly; and
  • do not extort, threaten, or condition disclosure on payment.

If you are unsure whether a specific action is covered, ask us first — we would much rather answer the question than have you guess.

We do not currently operate a paid bug bounty. Reports are handled on the terms above regardless.