VØIDDO · TRUST

security policy

If you've found a vulnerability, we want to hear from you. This page is our public commitment to how we handle security reports.

How to report

Email support@voiddo.com with the subject line "Security vulnerability report". One human reads that inbox.

Please include:

Our response

Scope

In scope:

Out of scope:

Safe harbor

If you make a good-faith effort to comply with this policy, we will not pursue legal action against you, even if your testing inadvertently violates other terms. Specifically, we agree to:

Please act in good faith — only test against your own accounts, don't access or modify other users' data, and let us know promptly if you accidentally do.

What we don't have

We're a small studio (6 people). We don't currently run a paid bug bounty program, we don't have a SOC 2 audit, and we don't have a dedicated security team. We do read every report and we fix what we find.

If you're evaluating us as an enterprise vendor and need formal security certifications, we're not the right fit yet. For everyone else — solo developers, agencies, small teams — we believe transparent disclosure and fast fixes matter more than badges.

Machine-readable

Our security.txt is at /.well-known/security.txt per RFC 9116.

Contact: support@voiddo.com
Subject line: "Security vulnerability report"
Languages: English, Russian