Found a security problem? Tell us.

This page is how to reach the people who can fix it, what we will do once you have written, and what we ask of you while you are looking. It applies to DoggySign and to everything served from this domain.

How to report it

Email info@doggysign.com and put the word security at the front of the subject line. Write in English. One report per problem keeps the thread readable when there is more than one.

You do not need an account to report something, and you do not need our permission to start looking. Nothing on this page asks you to agree to terms before you write to us.

The machine-readable version of this page is at /.well-known/security.txt.

What to put in it

The steps
Enough for somebody else to reproduce it from a cold start
What you saw
The response, the screen or the record that shows it worked
When
Roughly when you tried it, so we can find it in our own logs
Where
The address, and the account or agreement you used
Why it matters
What somebody could do with it, in your own words

A rough report with a real reproduction beats a polished one without. Send what you have.

What happens next

  1. Within three working days

    A reply from a person confirming we have your report, with a reference to quote.

  2. Within ten working days

    What we found when we tried to reproduce it, whether we agree it is a problem, and what we intend to do.

  3. While it is open

    An update whenever the position changes, and an answer to anything you ask in the meantime.

  4. When it is closed

    A note telling you what changed and when it shipped, or, if we decided against acting, our reasoning so you can argue with it.

Our thanks are public rather than paid. Tell us how you would like to be credited and we will name you here once the fix has shipped, or leave you out of it entirely if you would rather. If a report turns out to describe something working as intended, we will say so and explain why, which is a better answer than silence.

While you are looking

Research done inside these lines is welcome, and we will not go to a lawyer about it. They exist because the documents on this service belong to other people.

Use your own account and your own documents

Test against agreements you created and accounts you control. If a problem can only be shown by reaching somebody else’s data, stop at the point where you can see that it is possible and tell us then.

Take no more than you need to prove it

If you do reach data that is not yours, take the smallest amount that demonstrates the problem, tell us in the report exactly what you saw, and delete your copy once we have confirmed the report.

Leave the service standing

No denial of service, no load or stress testing, and no automated scanning heavy enough to slow the service down for anybody else. Somebody is trying to sign a contract on the other side of it.

No social engineering, and nothing physical

Do not phish our staff, our customers or our suppliers, do not attempt to talk your way past anybody, and do not try the offices or the post. The people who work here have not agreed to be tested.

Change nothing

Do not alter or delete data that is not yours, do not send agreements to people who did not ask for one, and do not leave test content behind on anybody else’s workspace.

Give us time before you publish

Please hold your write-up for ninety days from the day you report, or until we have shipped a fix, whichever comes first. If you have a reason to go sooner, say so in the report and we will work to your timetable rather than argue about it.

If you are not sure whether something you want to try falls inside these lines, write to us first and ask. For anything that is not a security problem, the support form reaches the same people and needs no account.

Reporting a security problem