Vulnerability disclosure policy

We verify identities for a living, so we take reports about our own security seriously. If you've found a vulnerability, tell us — we'll acknowledge it within one business day and we won't come after you for reporting it in good faith.

Report a Vulnerability security.txt

How to report.

Email security@withverifa.com. There is nothing to sign up for and no account to create. Please don't open a public issue, post it publicly, or raise it through sales or support channels first — send it here so it reaches the right people immediately.

What to include

Please don't send us personal data

If a vulnerability exposes someone's personal data, describe what you were able to access — don't attach it. Send a session ID or an internal reference instead of documents, names, or dates of birth. Access the minimum needed to demonstrate the issue and stop there.

Scope.

These are the systems we operate and can fix:

In scope

  • withverifa.com and its subdomains
  • app.withverifa.com — the dashboard
  • api.withverifa.com — the REST API and MCP server
  • capture.withverifa.com — the verification capture flow
  • Our embeddable JavaScript widget and published SDKs
  • Our Slack application

Out of scope

  • Third-party services we use but don't control — report those to the vendor
  • Findings from automated scanners with no demonstrated exploit path
  • Missing security headers, cookie flags, or TLS configuration with no demonstrated impact
  • Rate limiting on unauthenticated endpoints, absent a concrete attack
  • Social engineering of our staff or customers, and physical attacks
  • Denial of service, volumetric testing, or anything that degrades service for real users
  • Self-XSS, or issues requiring a compromised device or browser

Not sure whether something is in scope? Send it anyway. We'd rather read a report that turns out to be out of scope than miss one that matters.

Safe harbour.

If you follow this policy, we won't pursue you

We will not initiate legal action against you, or report you to law enforcement, for security research conducted in good faith under this policy. We consider such research authorised access under applicable computer misuse laws, and we will say so if a third party claims otherwise.

This holds as long as you: stay within the scope above; access the minimum data needed to demonstrate the issue and don't retain, copy, or share it; don't degrade service for our customers; don't extort, threaten, or publish before we've had a chance to fix it; and comply with the law.

If you act in good faith but accidentally overstep — you access more than you meant to, or you break something — tell us promptly and we'll treat it as part of the report, not as an attack.

What happens next.

These are commitments, not aspirations. Business days are Monday to Friday.

StageOur commitment
AcknowledgementWithin one business day, from a person, confirming we've received it
TriageWithin two business days we'll tell you whether we've reproduced it and what severity we've assigned
Remediation planAt triage we give you our intended timeline. Actively exploitable issues are handled as a security incident and start immediately
Progress updatesAt least every seven days until it's resolved or we've explained why we're not acting
ResolutionWe tell you when the fix ships, and confirm it addresses what you found

If we decide not to fix something, we'll tell you why rather than letting the thread go quiet. If we disagree on severity, we'll explain our reasoning and you're welcome to push back.

Disclosure and credit.

We ask that you give us a reasonable window to ship a fix before publishing — 90 days is our default, and we'll usually be far quicker. If a fix is taking longer than that, talk to us; we'd rather agree an extension openly than have a deadline pass in silence.

We're happy to credit you by name or handle in our release notes when a report leads to a fix, and equally happy not to if you'd rather stay anonymous. Just tell us which.

We don't run a bug bounty

There's no monetary reward for reports at this time, and we'd rather say that plainly up front than imply otherwise. What we do offer is a fast, human response, honest severity assessment, credit if you want it, and a fix.

Contact.

This policy applies to the systems listed under Scope and does not grant permission to test any other party's systems. It may be updated; the version in effect is the one published here. Last updated 20 August 2026.