Security
Security Policy
At DoyouKnowa, we take security seriously and are committed to protecting our users, systems, and data.
Report it responsibly to [email protected] and we’ll respond within 5 business days.
Reporting vulnerabilities
If you believe you have found a security vulnerability in our platform or services, we encourage you to report it to us responsibly.
Once received, our team triages every report by severity and potential impact, keeps you updated as we investigate, and confirms with you once a fix has been deployed. We follow the practices set out in the NCSC Vulnerability Disclosure Toolkit, the UK government’s standard guidance for handling security reports.
Responsible disclosure guidelines
We ask that you:
- Do not publicly disclose the issue before we’ve had a chance to investigate and fix it.
- Avoid privacy violations, destruction of data, or impacting other users.
We will:
- Respond within 5 business days.
- Provide updates as we work to resolve the issue.
- Acknowledge your contribution (if you wish) on our Hall of Fame.
Recommended report template
Please include the following when reporting:
Scope
In-scope
- doyouknowa.ai web app
- APIs under
doyouknowa.ai/api/*except for /api/chat - Authentication, session handling, or access control logic
Out of scope
- API /api/chat
- Denial of service attacks (DoS)
- Spam or social engineering of any kind
- Third-party services or libraries not under DoyouKnowa’s control
- Leaked passwords or breached credentials
Thank you
We appreciate the efforts of the security community to help us maintain a safe and trustworthy service.
Dated June 6th, 2025.
