Security
If you discover a security vulnerability in Docuplete, we want to hear from you. This page describes how to report it, what to expect from us, and the protections we extend to researchers who report in good faith.
How to report
Scope
The Docuplete marketing site and all pages under it.
The Docuplete application — org dashboard, client interview forms, signing flows, and the developer API (api.docuplete.com).
Issues affecting login, session management, token handling, or account isolation — including cross-tenant data access.
Any vulnerability that could expose client interview answers, generated PDFs, personally identifiable information, or API keys belonging to another organisation.
Injection, spoofing, or tampering affecting the PDF generation pipeline, field values, or signed document output.
Broken authentication, authorisation bypass, rate-limit bypass, or HMAC verification weaknesses in the developer API.
Out of scope
Phishing, vishing, or any attack targeting Docuplete employees or customers rather than the platform itself.
Volumetric or application-layer denial-of-service attacks against production infrastructure.
Vulnerabilities in third-party services we use (Cloudflare, Stripe, Clerk, etc.) should be reported directly to those vendors.
Attacks requiring physical access to hardware or infrastructure.
Please do not submit raw automated scanner output without a verified, reproducible finding.
Reports of vulnerabilities we have already acknowledged or that are publicly known without a new angle are out of scope.
Safe harbour
We take security seriously and respond to every credible report.
Email security@docuplete.comRelated