Vulnerability Disclosure Policy
Last updated: July 29, 2026
Our commitment
If you find a security vulnerability in the DOA application, our website, or our infrastructure, we want to hear about it. This page explains how to report one, what we will do, and what we ask of you.
We are a small operation. We do not run a paid bug bounty and cannot offer monetary rewards. What we can offer is a prompt human response, honest communication about what we are fixing and when, and public credit if you would like it.
How to report
Email support@deviceopticalaid.com with the subject line Security. A machine-readable version of this contact is published at /.well-known/security.txt.
To help us reproduce and fix the issue quickly, please include where you found it, the steps to reproduce it, what an attacker could achieve, and anything else we would need (a proof of concept, a screenshot, the affected version or URL). Reports in English or French are both fine.
What we will do
- Acknowledge your report within 5 business days
- Give you an initial assessment, including whether we consider it in scope, within 10 business days
- Keep you updated as we work on a fix, and tell you when it ships
- Credit you by name or handle when the fix is released, if you want that. If you prefer to stay anonymous, we will respect it
If a report affects personal data, we will also assess our obligations under GDPR Article 33, which may require notifying a supervisory authority within 72 hours.
Safe harbour
If you make a good-faith effort to follow this policy, we will not pursue or support legal action against you for your research, and we will treat your actions as authorised.
That authorisation covers research done within this policy. It does not extend to activity outside it. Accessing, copying, or retaining other people's data, altering or destroying data, disrupting the service for other users, or demanding payment in exchange for withholding a report are not security research, are not authorised here, and may be referred to the relevant authorities.
This commitment is ours to give and does not bind third parties. Our hosting, authentication, and payment providers run their own programmes, and testing that affects their systems falls under their rules rather than ours.
In scope
- The DOA Windows application
- deviceopticalaid.com and its subdomains
- Authentication, account, and subscription flows operated by us
Out of scope
The following are not accepted, usually because they are not exploitable, are owned by a third party, or are accepted risks we have already documented:
- Findings from automated scanners without a demonstrated, exploitable impact
- Missing security headers or best-practice suggestions with no practical attack behind them
- Denial of service, volumetric traffic, brute forcing, and anything degrading service for other users
- Social engineering, phishing, or physical attacks against us or our users
- Vulnerabilities in third-party services (Firebase, Creem, Resend, Vercel), which should be reported to those providers
- Reports requiring an already-compromised device, a rooted or jailbroken machine, or physical access to an unlocked computer
- The visible free-tier watermark and the documented usage limits, which are product behaviour rather than security flaws
What we ask of you
- Give us reasonable time to fix an issue before disclosing it publicly. We suggest 90 days, and will usually be much faster
- Use only your own accounts and test data. Do not access, modify, or retain anyone else's personal data
- If you encounter personal data by accident, stop, do not save it, and tell us in your report
- Do not degrade the service for other users or run destructive tests
- Do not demand payment in exchange for withholding a report. We treat that as extortion rather than research