> ## Documentation Index
> Fetch the complete documentation index at: https://docsautomator.co/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Responsible Disclosure

> How to report a security vulnerability in DocsAutomator

We take the security of DocsAutomator and our customers' data seriously and appreciate responsible reports.

## How to report

Email a description of the issue to **[support@docsautomator.co](mailto:support@docsautomator.co)** with the subject "Security report". Please include:

* Steps to reproduce the issue
* The affected URL or endpoint
* The potential impact as you assess it

We confirm receipt, investigate every legitimate report, and let you know the outcome.

## Ground rules

* Do not access, modify, or exfiltrate data that is not your own. Use test accounts.
* No automated scanning that degrades the service, and no denial-of-service testing.
* No social engineering of DocsAutomator staff or customers.
* Give us reasonable time to fix an issue before any public disclosure.

## Bounty

DocsAutomator does **not** operate a paid bug bounty program, and we do not pay for unsolicited reports. Reports of the following without a demonstrated security impact are out of scope and will not receive a detailed response:

* Missing security headers, SPF/DKIM/DMARC configuration remarks
* Clickjacking on pages without sensitive actions
* Version disclosure or other output from automated scanners without a proof of concept

Genuine vulnerabilities with real impact are fixed with priority, and we are happy to credit the reporter if desired.
