Security & Vulnerability Disclosure

Last updated: May 6, 2026

We take the security of Dr. Vin seriously. If you believe you've found a security issue, we want to hear from you.

Reporting a vulnerability

Email security@drvin.ai with:

We acknowledge reports within 5 business days and aim to fix high-severity issues within 30 days.

Scope

In scope:

Out of scope:

Rules of engagement

Safe harbor

We won't pursue legal action against researchers who make a good-faith effort to comply with this policy, stop testing once a vulnerability is identified, and report findings through the channel above. We treat compliant research as authorized under the Computer Fraud and Abuse Act and similar laws.

Bounty & credit

We don't currently run a paid bug bounty program. We do credit researchers who report valid issues (with permission) once the fix ships.

Machine-readable

Our security.txt file is at /.well-known/security.txt per RFC 9116.