Skip to content

Responsible Disclosure Policy

Effective date: Oct 7, 2026
Last updated: Oct 7, 2026

We want to hear about security problems in Docdrift. If you find one and follow this policy, we'll work with you to fix it and we won't take legal action against you. Docdrift is operated by Un martes a las 10 am, S.A. de C.V.

How to report

Email [email protected]. If that address doesn't work for you, use [email protected] with "Security" in the subject. Our machine-readable contact file is at https://docdrift.io/.well-known/security.txt.

Please include:

  • what you found and where (URL, endpoint or component);
  • the steps to reproduce it;
  • the impact you think it has;
  • whether you accessed any data that isn't yours, and what you did with it.

Write in English. We don't offer an encrypted channel at this time, so don't include other people's data in your report: describe it instead.

In scope

  • docdrift.io, app.docdrift.io, mcp.docdrift.io and hooks.docdrift.io.
  • The Docdrift and Docdrift Write GitHub Apps.
  • The Docdrift MCP server, agent hooks and the connector for Claude and ChatGPT.
  • The Docdrift Verified pages and badges.
  • Leaked Docdrift agent tokens (they start with dd_mcp_).

Out of scope

  • Services we use but don't run, such as GitHub, Notion, Google, Stripe, Cloudflare and Resend. Report those to their owners.
  • Denial-of-service attacks, load testing and spam.
  • Social engineering, phishing and physical attacks.
  • Findings from automated scanners without a working proof of concept.
  • Missing security headers, email authentication settings (SPF, DKIM, DMARC) or version banners without a demonstrated impact.
  • Clickjacking on pages without sensitive actions, self-XSS and logout CSRF.
  • Rate limits you can only get around with a large number of IP addresses.

Rules for testing

  • Test only against accounts and workspaces you created. Use your own repositories, docs and websites.
  • Don't access, change or delete data that isn't yours. If you reach someone else's data by accident, stop, don't keep a copy, and tell us.
  • Don't degrade the service for others. Keep automated requests slow and respect rate limits.
  • Don't try to break out of our analysis sandbox with code meant to damage our systems. Tell us what you'd try instead, and we'll set up a safe test.
  • Give us a reasonable time to fix the issue before you share it publicly. We ask for 90 days from your report, or less if we tell you the fix is live.
  • Follow the law that applies to you.

What we commit to

  • We confirm we received your report within 3 business days.
  • We tell you whether we confirm the issue, and our plan, within 10 business days.
  • We keep you updated until it's fixed.
  • If you want, we credit you by name when we announce the fix.
  • We don't pay bug bounties at this time.

Safe harbor

If you act in good faith and follow this policy, we consider your research authorized, we won't bring legal action against you for it, and we won't report you to law enforcement. If someone else brings a claim over research that followed this policy, we'll say publicly that it was authorized. This authorization covers only Docdrift's own systems, not the third-party services listed above. If you're not sure whether something is allowed, ask us first at [email protected].