Reporting a vulnerability
If you discover a cybersecurity issue affecting dakkda products, infrastructure, or the public websites (dakkda.com or help.dakkda.com), please report it to security@dakkda.com as soon as possible. dakkda appreciates the efforts of cybersecurity researchers and the broader community who help keep dakkda customers safe.
Cybersecurity contact
Use this address for vulnerability reports, privacy inquiries, and terms-related questions.
Machine-readable contact: /.well-known/security.txt · encrypt sensitive reports with the PGP public key.
What to include
To help dakkda investigate quickly, please provide:
- A clear description of the vulnerability and its potential impact
- Step-by-step instructions to reproduce the issue
- Affected URLs, endpoints, or components (if applicable)
- Proof-of-concept code or screenshots, if available
- Your contact information so dakkda can follow up
Please encrypt sensitive details if your report contains customer data or exploit code. Use the dakkda PGP public key at /.well-known/pgp-key.txt (also linked from /.well-known/security.txt).
dakkda’s commitment
When you report a vulnerability in good faith, dakkda commits to:
- Acknowledge receipt within 3 business days
- Provide a status update within 10 business days
- Work with you to understand and remediate validated issues
- Not pursue legal action against researchers who comply with this policy and avoid privacy violations, data destruction, or service disruption
Scope
In scope
- dakkda-owned web properties listed on this site
- dakkda platform and API endpoints operated by dakkda
- Official dakkda infrastructure disclosed to customers
Out of scope
- Third-party services and integrations not operated by dakkda
- Social engineering or phishing attacks against dakkda employees
- Denial-of-service (DoS/DDoS) attacks
- Physical cybersecurity testing
- Issues requiring physical access to a customer’s environment
- Automated scanning that materially degrades service availability
Safe harbor
dakkda considers cybersecurity research conducted in accordance with this policy to be authorized. Do not access, modify, or delete data that does not belong to you. Stop testing once you have demonstrated a vulnerability and notify dakkda immediately. dakkda asks that you do not publicly disclose issues until dakkda has had a reasonable opportunity to remediate them.
Recognition
dakkda is grateful for responsible disclosures. With your permission, dakkda may acknowledge researchers who help improve dakkda cybersecurity. dakkda does not currently operate a paid bug bounty program.
See also the Legal Notice, Privacy Policy, Cookie Policy, and Terms of Service.