Vulnerability Disclosure Policy
Updated 5 Jul 2026
Sudory welcomes security research conducted in good faith. This policy tells researchers how to report vulnerabilities and what to expect from us, and implements ISO/IEC 27001:2022 Annex A controls 5.5, 5.6 and supports 8.8.
How to report
Email trust@sudory.com with a description of the issue, steps to reproduce, and the affected URL or component. Encrypted reports are accepted; ask for our key in a first message if needed. We confirm receipt within two working days.
Scope
In scope: sudory.com, the Sudory application, public trust pages, and Sudory-operated scanner infrastructure.
Out of scope: our suppliers’ platforms (report to them directly), social engineering of people, physical attacks, and denial of service.
Rules of engagement
Do not access, modify, or delete data that is not yours; use test accounts wherever possible.
Stop and report as soon as you can demonstrate the issue; do not pivot deeper to prove impact.
Give us reasonable time to fix before any public disclosure; we aim for coordinated disclosure within 90 days.
Our commitments
We will not pursue legal action against research that follows these rules.
We keep you informed: triage verdict within five working days, and progress updates until resolution.
We credit researchers who want credit once a fix is released; we do not currently pay bounties.
Handling internally
Reports enter the incident management process, are risk-assessed, fixed with priority matching their severity, and feed the vulnerability management loop described in the Hardening Policy.