Security policy & responsible disclosure
How to report
Email security@dorsey-worx.com. Please include enough detail to reproduce the issue: affected URL or endpoint, steps you took, and what you expected vs. what actually happened. We acknowledge good-faith reports within 3 business days.
Scope
This policy covers the production Recovery Console application:
app.dorsey-worx.com— the customer-facing console.- Public marketing surfaces under
dorsey-worx.com. - Authenticated APIs under
app.dorsey-worx.com/api/*.
Out of scope:
- Reports based on outdated information or staging environments.
- Findings from automated scanners without a working proof-of-concept.
- Social engineering, phishing, or physical-access attacks.
- Issues already publicly disclosed.
- Self-XSS, missing best-practice headers without measurable impact.
- Denial-of-service via volumetric attacks.
Safe harbor
We will not pursue legal action against researchers who follow this policy, do not access more data than necessary to demonstrate the issue, do not retain or publicly disclose data, and give us a reasonable opportunity to remediate before publication. By "reasonable opportunity" we mean at least 90 days from acknowledgment, or earlier if the issue has been remediated.
What you can expect
- Acknowledgment within 3 business days.
- Triage and severity assessment within 7 business days.
- Remediation targets: critical (CVSS ≥ 9.0) within 14 days, high (7.0–8.9) within 30 days, medium (4.0–6.9) within 90 days, low (≤ 3.9) on next available release.
- Public credit on a coordinated disclosure timeline if you want it.
- No bug bounty program at this time. We may revisit as the product matures.
Incident response
If we confirm a security incident affecting customer data, we will:
- Notify affected customers within 72 hours of confirmation.
- Provide a written incident summary with root cause, scope, and remediation steps.
- File regulatory notifications where applicable (CCPA §1798.82 and equivalents).
Related policies
- Data residency, retention & sub-processors — where data is stored, how long it's kept, and who else processes it.
- Incident response — severity tiers, customer notification timelines, post-mortem commitments.
- Privacy notice — what data we collect, why, and your rights.
- Terms of service — the contract that governs your use of the Service.
- AI / ML disclosure — how Recovery Console uses machine learning.
- SMS terms & consent — TCPA-aligned consent and opt-out.