dohosGet started
PLATE Nº 121

Report a security issue, or ask before you do

For a security question, or a report that isn't yet a formal vulnerability submission — a suspicion something's off, a request for detail before writing something up properly, or a finding ready for the real process. This page is not itself the disclosure process; it's the door in front of it, for everything that hasn't reached that stage — or never needs to.

PLATE Nº 121 · SECURITY
THE SECURITY DOORONE MESSAGE · ONE READER
A PLACEHOLDER NAME DOESN'T STOP A MESSAGE FROM BEING READ
THE ONLY CONTACT DETAIL THIS FORM ASKS FOR BEYOND A NAME
WHAT THIS IS
“I'M NOT SURE THIS IS REAL” IS A COMPLETELY NORMAL THING TO WRITE. A MINIMAL PROOF OF CONCEPT HELPS BUT ISN'T REQUIRED.

READ BY A PERSON · NO RESPONSE-TIME FIGURE EXISTS, SO NONE IS PROMISED

WHAT THIS IS, NEXT TO WHAT IT ISN'T

The real substance of how Dohos handles a security report lives at vulnerability disclosure — what's in scope, what safe harbor covers, what happens once a report is in. This page routes into it; it doesn't restate it. A report that turns out to be out of bounds, or testing that crossed a line the policy draws on purpose, is a worse outcome for everyone than checking first.

THE DISCLOSURE POLICYThe complete process: scope, the conditions that keep good-faith research treated as research, and what happens after a report arrives. This page's dominant neighbor — read it before testing anything.
SCOPEWhether something is even in bounds to report starts there, not here — a quick read saves a reply that would just point back at the same page.
SAFE HARBORThe specific conditions under which testing is treated as protected research live on that page too, not summarized differently here.
NO BOUNTY PROGRAMNamed honestly, not folded quietly into “scope.” Nothing pays out for a finding today, and this page doesn't imply one is quietly available to the right person who asks.
THE HONEST WHOLE TRUTH ABOUT THIS CHANNEL

Security researchers read a vague or overconfident “contact us” page as a signal nobody's thinking about this seriously — and the honest version, stated directly, reads as more credible than a confident-sounding promise with nothing behind it. A report sent here is read by a person who can act on it; it just isn't triaged by a team whose sole job is security response, and it doesn't carry a published number for how fast that response happens.

For a reviewer running a vendor-security process: the vendor packet gathers the documents that review typically asks for — the legal terms, the privacy and security policies, the signable contracts, the subprocessor register — each a live page carrying its own real draft status. What a reviewer won't find there, because none exists: a SOC 2 report, an independent penetration-test summary, a certificate of insurance. Not left out of the bundle — genuinely absent. A specific question about what a particular gap means is exactly what this page is for.

Where the question is really about the contract itself rather than security posture — a term that needs to move, the state of a specific clause — legal is the more direct door.

QUESTIONS WORTH ASKING FIRST
Is there a bug bounty?

No. Nothing pays out for a finding today.

How fast will someone respond?

No figure exists to give. A well-described report is read and triaged by severity, not queued behind a published number that doesn't exist to promise in the first place.

I'm not sure this is even a real vulnerability — can I still ask?

Yes. This page exists specifically for that uncertainty; a question that turns out to be nothing is a normal use of this door, not a wasted one.

Should I include a proof of concept?

A minimal one helps — stopping at the point that demonstrates the issue rather than continuing further into it. A clear description on its own is still enough to start with.

Can I stay anonymous?

An email address is the only contact detail asked for beyond a name, and a name that's clearly a placeholder doesn't stop a message from being read.

What doesn't belong here?

A suspicious call, a fraudulent-looking order, or a billing charge that doesn't look right — those go to support or billing; they're account situations, not platform findings. A mislabeled account question still gets redirected honestly.

BEFORE YOU WAIT ON A REPLY

For an existing account with a specific, live symptom, the help section often gets to a fix faster than a message and a reply — it walks the exact screens, step by step.