Vulnerability disclosure policy, scope, and safe harbour. RFC 9116 and ISO/IEC 29147 aligned.
If you have discovered a vulnerability in Dokima (the public scanner, the API, the badge endpoint, the CLI, the frontend, or our infrastructure), email us at [email protected] with as much detail as you can share. The well-known machine-readable contact point is /.well-known/security.txt per RFC 9116.
We follow a two-stage acknowledgement process aligned with RFC 9116 and ISO/IEC 29147 vulnerability-disclosure norms.
DKM-VDP-YYYYMMDD-XXXX and an estimated triage window. Quote the tracking identifier in any follow-up so we can correlate fast.A useful report typically contains:
A short, well-structured report is more valuable than an exhaustive one — send what you have; we will ask follow-ups.
We will not pursue legal action against good-faith security researchers who follow this disclosure process. To qualify for safe harbour you should:
Outside good-faith research, the Acceptable Use Policy applies and conduct may constitute an offence under the Computer Misuse Act 1990. The Acceptable Use Policy governs what testing is permitted without prior written authorisation.
In scope:
dokima.dev and all subdomainsOut of scope:
At our discretion, and with the reporter's consent, we credit researchers in our security acknowledgements (a public list, this page, lower on this page). The acknowledgements section is empty at launch; submissions accepted from day one.
No public acknowledgements yet. Submit a finding to be the first.