Legal

Reporting a Security Issue

Effective September 22, 2026

Reporting a security issue

If you have found a vulnerability in verdocs.com, app.verdocs.com, or the Verdocs API, email support@verdocs.com. Include the affected system, the steps to reproduce it, and what an attacker could do with it. A report we can reproduce gets fixed; a report we cannot reproduce gets a request for more detail.

What we are seeing, and what we will not do

Most reports we receive are the output of automated scanners run against many companies at once: missing headers, version banners, best-practice suggestions, and issues that require a victim to already be compromised. These do not describe a vulnerability in our systems and they do not receive a reply.

Verdocs does not run a bug bounty program and does not pay for reports. We do not commit to a response time, and we do not provide public acknowledgment. We read every report that describes a real, reproducible issue specific to our systems, and we fix what we confirm.

What our customers can rely on

Verdocs holds a SOC 2 Type I attestation, with the report available under a mutual NDA. Signing keys are held in hardware security modules. The rest of our controls are described on the legal and compliance page.