Back to home

Vulnerability Disclosure Policy

Last updated: July 2026

We take the security of our customers' confidential documents seriously and welcome good-faith research that helps us keep them safe. This policy explains how to report a vulnerability and what you can expect from us.

How to report

Email security@sifrsys.com with a description of the issue, the steps to reproduce it, and its potential impact. Please encrypt sensitive details on request. Our machine-readable contact is at /.well-known/security.txt.

Our commitment

  • We will acknowledge your report within 3 business days.
  • We will keep you informed as we investigate and remediate.
  • We will not pursue legal action against researchers who follow this policy in good faith.
  • We are happy to credit you once the issue is resolved, if you wish.

Please do

  • Give us a reasonable time to remediate before any public disclosure.
  • Only test against your own accounts and data.
  • Report as soon as you discover a potential issue.

Please do not

  • Access, modify, or delete data belonging to other customers.
  • Degrade or disrupt our services (no denial-of-service or spam testing).
  • Use social engineering, phishing, or physical attacks against our staff or vendors.
  • Publicly disclose a vulnerability before we have had a chance to fix it.

Scope

The Sifrsys production application (sifrsys.com and its subdomains) and its API are in scope. Third-party services we rely on (our hosting, database, email, and payment providers) have their own disclosure programs and should be reported to them directly.