Trust Center
Responsible Disclosure
We take security seriously and welcome reports from researchers who discover a vulnerability in our platform, provided they follow the process below.
How to Report
Email it.support@dpoboard.com with a description of the issue, the steps to reproduce it, and any supporting material (screenshots, request/response logs, proof-of-concept code). Please do not include actual client or personal data in your report — describe the issue in the abstract wherever possible.
What to Expect
We aim to acknowledge reports within 5 business days and will follow up with our assessment and, where applicable, an estimated remediation timeline. We'll keep you informed of significant progress until the issue is resolved.
Safe Harbor
We will not pursue legal action against researchers who make a good-faith effort to comply with this policy: report through the channel above, avoid privacy violations, data destruction, or service disruption, only interact with accounts and data you own or have explicit permission to test, and give us reasonable time to investigate and remediate before any public disclosure.
Out of Scope
- Denial-of-service testing or any testing that degrades service for others.
- Social engineering of our staff, contractors, or clients.
- Physical attacks against our offices or infrastructure providers.
- Automated scanning that generates significant traffic without prior coordination.