We verify identities for a living, so we take reports about our own security seriously. If you've found a vulnerability, tell us — we'll acknowledge it within one business day and we won't come after you for reporting it in good faith.
Email security@withverifa.com. There is nothing to sign up for and no account to create. Please don't open a public issue, post it publicly, or raise it through sales or support channels first — send it here so it reaches the right people immediately.
If a vulnerability exposes someone's personal data, describe what you were able to access — don't attach it. Send a session ID or an internal reference instead of documents, names, or dates of birth. Access the minimum needed to demonstrate the issue and stop there.
These are the systems we operate and can fix:
Not sure whether something is in scope? Send it anyway. We'd rather read a report that turns out to be out of scope than miss one that matters.
We will not initiate legal action against you, or report you to law enforcement, for security research conducted in good faith under this policy. We consider such research authorised access under applicable computer misuse laws, and we will say so if a third party claims otherwise.
This holds as long as you: stay within the scope above; access the minimum data needed to demonstrate the issue and don't retain, copy, or share it; don't degrade service for our customers; don't extort, threaten, or publish before we've had a chance to fix it; and comply with the law.
If you act in good faith but accidentally overstep — you access more than you meant to, or you break something — tell us promptly and we'll treat it as part of the report, not as an attack.
These are commitments, not aspirations. Business days are Monday to Friday.
| Stage | Our commitment |
|---|---|
| Acknowledgement | Within one business day, from a person, confirming we've received it |
| Triage | Within two business days we'll tell you whether we've reproduced it and what severity we've assigned |
| Remediation plan | At triage we give you our intended timeline. Actively exploitable issues are handled as a security incident and start immediately |
| Progress updates | At least every seven days until it's resolved or we've explained why we're not acting |
| Resolution | We tell you when the fix ships, and confirm it addresses what you found |
If we decide not to fix something, we'll tell you why rather than letting the thread go quiet. If we disagree on severity, we'll explain our reasoning and you're welcome to push back.
We ask that you give us a reasonable window to ship a fix before publishing — 90 days is our default, and we'll usually be far quicker. If a fix is taking longer than that, talk to us; we'd rather agree an extension openly than have a deadline pass in silence.
We're happy to credit you by name or handle in our release notes when a report leads to a fix, and equally happy not to if you'd rather stay anonymous. Just tell us which.
There's no monetary reward for reports at this time, and we'd rather say that plainly up front than imply otherwise. What we do offer is a fast, human response, honest severity assessment, credit if you want it, and a fix.