Sudory logo

Sudory

Trust Center

Request access

Vulnerability Disclosure Policy

Updated 5 Jul 2026

Sudory welcomes security research conducted in good faith. This policy tells researchers how to report vulnerabilities and what to expect from us, and implements ISO/IEC 27001:2022 Annex A controls 5.5, 5.6 and supports 8.8.

How to report

Email trust@sudory.com with a description of the issue, steps to reproduce, and the affected URL or component. Encrypted reports are accepted; ask for our key in a first message if needed. We confirm receipt within two working days.

Scope

  • In scope: sudory.com, the Sudory application, public trust pages, and Sudory-operated scanner infrastructure.

  • Out of scope: our suppliers’ platforms (report to them directly), social engineering of people, physical attacks, and denial of service.

Rules of engagement

  • Do not access, modify, or delete data that is not yours; use test accounts wherever possible.

  • Stop and report as soon as you can demonstrate the issue; do not pivot deeper to prove impact.

  • Give us reasonable time to fix before any public disclosure; we aim for coordinated disclosure within 90 days.

Our commitments

  • We will not pursue legal action against research that follows these rules.

  • We keep you informed: triage verdict within five working days, and progress updates until resolution.

  • We credit researchers who want credit once a fix is released; we do not currently pay bounties.

Handling internally

Reports enter the incident management process, are risk-assessed, fixed with priority matching their severity, and feed the vulnerability management loop described in the Hardening Policy.