Responsible reporting

Report a Security Concern

Send potential vulnerability reports to DocuLens security. Include a concise description, affected surface and version, reproducible steps, and the impact you observed.

Protect customer information

Do not include customer documents, photographs, credentials, activation keys, access tokens, or other sensitive information in the initial report. DocuLens will provide an approved secure transfer path if additional evidence is necessary.

Good-faith testing

Avoid privacy violations, service disruption, social engineering, destructive testing, persistent access, or accessing data that does not belong to you. Stop testing and report promptly when sensitive data may have been exposed.

What to expect

DocuLens will acknowledge reports, assess severity and scope, coordinate remediation and disclosure where appropriate, and may request additional information. This page does not authorize testing that would otherwise be unlawful or violate third-party terms.