Legal
Responsible Disclosure
We take the security of Verifycate seriously, and we appreciate the work of security researchers. If you believe you've found a vulnerability, we want to hear about it — and we promise to work with you, not against you.
Scope
This policy covers the Verifycate website, the app dashboard, the API at api.verifycate.dev, public certificate verification pages (including /verify and individual certificate pages), the recipient portal, and the developer documentation site.
Anything outside these properties — including third-party services we rely on — should be reported to the respective provider under their own disclosure policy.
How to report
Email [email protected] with as much of the following as you can provide: a description of the vulnerability, the steps to reproduce it, the affected URL or endpoint, and your assessment of the impact.
If you'd like to send an encrypted report, email us first and we'll share a PGP key. Please don't include other people's data in reports or screenshots.
What to expect
We'll acknowledge receipt as soon as we can, keep you informed as we investigate and fix the issue, and let you know once it's resolved. Complex issues can take a while — we'd rather give you an honest status than a deadline we miss.
Safe harbor
If you make a good-faith effort to comply with this policy during your research, we will consider your activity authorized and won't pursue legal action against you.
To stay within safe harbor, please: use only your own accounts and test data, don't access, modify, or exfiltrate data that isn't yours — stop and tell us immediately if you encounter any, avoid degrading the service for other users, and give us a reasonable amount of time to fix the issue before any public disclosure.
Out of scope
The following findings are generally not treated as security vulnerabilities under this policy:
- Spam, social engineering, phishing, or physical attacks.
- Denial-of-service attempts or brute-force attacks.
- Missing security headers or cookie flags without a demonstrable exploit.
- Self-XSS and issues that require an attacker to already control the victim's account.
- Automated scanner output without a demonstrated, reproducible issue.
- Rate limiting, or the lack of it, where no sensitive action is at risk.
Recognition
If you'd like, we're happy to credit you — by name or handle, with a link if you prefer — once the issue is fixed. Anonymous reports are equally welcome; just let us know your preference in the report.
Verifycate does not run a paid bug bounty program, so reports are voluntary and unpaid.
Report an issue
Send vulnerability reports to [email protected]. If it's easier, you can also reach us at [email protected] — mark it clearly as a security report.