Responsible disclosure
If you have found a weakness in our service, we would rather hear it from you than from a customer. This policy describes how to tell us and what we promise in return.
How to report
Email security@doc-share.online, encrypted with our PGP key if the finding is sensitive. Include enough detail to reproduce: the affected address, the steps, the observed result, and what you believe the impact is. Screenshots and a short video help. Please write in Dutch or English.
PGP fingerprint: 4A7F 2C19 8D3B 66E0 1F52 90AC B471 D8E3 55FA 2100
Key: https://www.doc-share.online/.well-known/pgp-key.txt
What we commit to
- Acknowledgement within one business day.
- A triage verdict with severity within five business days.
- Progress updates at least every two weeks until it is closed.
- Remediation targets: critical within 24 hours, high within 7 days, medium within 30 days.
- Credit in our advisory and on our researcher wall, if you want it.
- A bounty where the finding is in scope and previously unknown — €250 to €15,000 depending on severity and quality of the report.
Safe harbour
If you act in good faith, stay within the scope below, and give us reasonable time to remediate before publishing, we will not pursue legal action against you and will not report you to law enforcement. If a third party brings action against you for research conducted within this policy, we will make that fact known.
In scope
www.doc-share.onlineand the marketing site*.doc-share.onlinerecipient viewersapi.doc-share.online- The sender console and the Outlook add-in
- Our published mobile and desktop clients
Out of scope
- Denial of service, volumetric testing, or anything that degrades availability for others
- Social engineering of our staff, customers or recipients, and physical intrusion
- Automated scanner output with no demonstrated impact
- Missing headers, cookie flags or TLS configuration findings without a working exploit path
- Vulnerabilities in a customer's own systems, or in documents they have sent
- Reports that require a compromised device or a malicious browser extension
Rules
- Use only your own test accounts and your own test documents. We will provide a sandbox tenant on request.
- Do not access, modify or retain data belonging to anyone else. If you stumble on real data, stop, and tell us what you saw so we can assess it.
- Do not attempt to brute-force a passphrase against a live share.
- Give us ninety days before public disclosure, or less by agreement if the fix ships sooner.
Already known
Our security page documents several deliberate limits — passphrase recovery is impossible by design, screenshots cannot be prevented, and plaintext search is not offered. These are choices rather than defects, and reports about them will be closed as such, with thanks.