How to report
Email a description of the issue to support@docsautomator.co with the subject “Security report”. Please include:- Steps to reproduce the issue
- The affected URL or endpoint
- The potential impact as you assess it
Ground rules
- Do not access, modify, or exfiltrate data that is not your own. Use test accounts.
- No automated scanning that degrades the service, and no denial-of-service testing.
- No social engineering of DocsAutomator staff or customers.
- Give us reasonable time to fix an issue before any public disclosure.
Bounty
DocsAutomator does not operate a paid bug bounty program, and we do not pay for unsolicited reports. Reports of the following without a demonstrated security impact are out of scope and will not receive a detailed response:- Missing security headers, SPF/DKIM/DMARC configuration remarks
- Clickjacking on pages without sensitive actions
- Version disclosure or other output from automated scanners without a proof of concept