Vulnerability Disclosure Policy
doo welcomes reports from security researchers and customers who discover vulnerabilities in our products or infrastructure.
Scope
This policy covers the doo event management platform, including the doo.net website, customer-facing applications, APIs, and services operated by doo.
The following are out of scope: services operated by third parties, findings produced solely by automated scanners without demonstrated impact, missing security headers with no exploitable consequence, and social engineering attacks targeting our staff or customers.
Reporting
Send reports to security@doo.net, in English, with enough detail to reproduce the issue: the affected product, domain or version, what an attacker could achieve, and how we can reach you. A finished exploit or a severity rating is not required.
We acknowledge reports promptly, share an initial assessment once we have triaged the issue, and keep you informed of progress until it is closed.
What we ask
Report privately and give us the opportunity to remediate before any publication. Stop once you have shown that the issue exists. Do not access, modify or delete data that is not your own, and do not retain personal data you encounter; if you come across personal data, stop and tell us. Avoid any action that could degrade our services.
Safe harbor
doo will not pursue legal action against research conducted in good faith and in line with this policy. If a third party takes action over research that met this policy, we will make that authorisation clear.
Recognition
This is not a bug bounty programme. We do not offer financial rewards or other compensation.
How we handle reports
We review all reports submitted in good faith. If a security issue is confirmed, we will assess its impact and take appropriate remediation measures. We will make reasonable efforts to keep the reporter informed throughout the process.
Contact and updates
Our contact details are also published at https://www.doo.net/.well-known/security.txt in the format described in RFC 9116. The effective date of this document tells you which version you are reading.


