Report a security issue, or ask before you do
For a security question, or a report that isn't yet a formal vulnerability submission — a suspicion something's off, a request for detail before writing something up properly, or a finding ready for the real process. This page is not itself the disclosure process; it's the door in front of it, for everything that hasn't reached that stage — or never needs to.
READ BY A PERSON · NO RESPONSE-TIME FIGURE EXISTS, SO NONE IS PROMISED
The real substance of how Dohos handles a security report lives at vulnerability disclosure — what's in scope, what safe harbor covers, what happens once a report is in. This page routes into it; it doesn't restate it. A report that turns out to be out of bounds, or testing that crossed a line the policy draws on purpose, is a worse outcome for everyone than checking first.
Security researchers read a vague or overconfident “contact us” page as a signal nobody's thinking about this seriously — and the honest version, stated directly, reads as more credible than a confident-sounding promise with nothing behind it. A report sent here is read by a person who can act on it; it just isn't triaged by a team whose sole job is security response, and it doesn't carry a published number for how fast that response happens.
For a reviewer running a vendor-security process: the vendor packet gathers the documents that review typically asks for — the legal terms, the privacy and security policies, the signable contracts, the subprocessor register — each a live page carrying its own real draft status. What a reviewer won't find there, because none exists: a SOC 2 report, an independent penetration-test summary, a certificate of insurance. Not left out of the bundle — genuinely absent. A specific question about what a particular gap means is exactly what this page is for.
Where the question is really about the contract itself rather than security posture — a term that needs to move, the state of a specific clause — legal is the more direct door.
Is there a bug bounty?
No. Nothing pays out for a finding today.
How fast will someone respond?
No figure exists to give. A well-described report is read and triaged by severity, not queued behind a published number that doesn't exist to promise in the first place.
I'm not sure this is even a real vulnerability — can I still ask?
Yes. This page exists specifically for that uncertainty; a question that turns out to be nothing is a normal use of this door, not a wasted one.
Should I include a proof of concept?
A minimal one helps — stopping at the point that demonstrates the issue rather than continuing further into it. A clear description on its own is still enough to start with.
Can I stay anonymous?
An email address is the only contact detail asked for beyond a name, and a name that's clearly a placeholder doesn't stop a message from being read.
For an existing account with a specific, live symptom, the help section often gets to a fix faster than a message and a reply — it walks the exact screens, step by step.