Vulnerability Disclosure Policy

Version 1.0Effective July 20, 2026Last reviewed July 20, 2026

Responsible disclosure and vulnerability reporting process.

Reporting process

Report vulnerabilities to [email protected] with sufficient detail to reproduce the issue. Encrypt sensitive reports using PGP upon request.

Scope

This policy covers DotlyMaps production services and official web properties. Out-of-scope: social engineering, physical attacks, denial of service, and third-party services outside our control.

Expected response times

We acknowledge reports within 5 business days. Status updates are provided as investigation progresses.

Responsible disclosure

Please allow reasonable time for remediation before public disclosure. We coordinate disclosure timelines with researchers when possible.

Safe harbor

DotlyMaps will not pursue legal action against researchers who act in good faith, avoid privacy violations, and comply with this policy.