Skip to content
VendoCerta

Security

Found a security vulnerability? We want to know.

We value security researchers who report issues responsibly instead of publishing or exploiting them. This page describes how to do that and what you can expect from us.

Last updated: 21 August 2026

How to report

Send a description to contact@autodreamgroup.com, with "[SECURITY]" in the subject line. This is the same contact address we use for everything else — we do not yet have a dedicated security mailbox, so please use that tag so your report reaches the right person straight away.

In your report, please describe: what you found, how to reproduce it step by step, the potential impact, and, if possible, a suggested fix. Screenshots and logs help a lot.

What this program covers

The vendocerta.com website, and the VendoCerta product to the extent you are testing it on your own, self-hosted instance. It does not cover instances belonging to other customers — testing someone else's installation without their consent is outside this program and may be unlawful.

What not to do

Please don't test in a way that could harm the availability of the site or of other people's data (denial-of-service attacks, mass scanning, social-engineering attempts against staff). Don't access data that isn't yours beyond the minimum needed to demonstrate the vulnerability, and please don't publish details before the issue is fixed.

What you can expect from us

We will try to acknowledge your report and keep you updated on progress within a reasonable time. Good-faith reports that follow the rules above will not lead to legal action from us — this is our safe harbor for researchers acting responsibly.

We do not currently run a formal paid bug-bounty program. We do value reports and, if you'd like, are happy to credit you by name once an issue is fixed.