Skip to main content
We take the security of DocsAutomator and our customers’ data seriously and appreciate responsible reports.

How to report

Email a description of the issue to support@docsautomator.co with the subject “Security report”. Please include:
  • Steps to reproduce the issue
  • The affected URL or endpoint
  • The potential impact as you assess it
We confirm receipt, investigate every legitimate report, and let you know the outcome.

Ground rules

  • Do not access, modify, or exfiltrate data that is not your own. Use test accounts.
  • No automated scanning that degrades the service, and no denial-of-service testing.
  • No social engineering of DocsAutomator staff or customers.
  • Give us reasonable time to fix an issue before any public disclosure.

Bounty

DocsAutomator does not operate a paid bug bounty program, and we do not pay for unsolicited reports. Reports of the following without a demonstrated security impact are out of scope and will not receive a detailed response:
  • Missing security headers, SPF/DKIM/DMARC configuration remarks
  • Clickjacking on pages without sensitive actions
  • Version disclosure or other output from automated scanners without a proof of concept
Genuine vulnerabilities with real impact are fixed with priority, and we are happy to credit the reporter if desired.
Last modified on July 22, 2026