# Dollar Loanz — coordinated vulnerability disclosure # # Thank you for looking. The full policy, including scope, response times # and our safe-harbor commitment, is at the Policy URL below. # # Please put "[SECURITY]" at the front of your subject line. Contact: mailto:support@dollarloanz.com Expires: 2027-09-14T00:00:00.000Z Policy: https://www.dollarloanz.com/security/report Canonical: https://www.dollarloanz.com/.well-known/security.txt Preferred-Languages: en Acknowledgments: https://www.dollarloanz.com/security/report#acknowledgements # In scope # - dollarloanz.com and www.dollarloanz.com # - The public application flow and everything under it # - The customer portal, once it is open to customers # - Any API endpoint served from those hosts # Out of scope # - Anything that needs a denial-of-service, a load test or brute force to demonstrate — tell us the theory instead and we will take it seriously # - Social engineering of our staff, our customers or our suppliers # - Physical attempts against any premises or person # - Reports generated wholly by an automated scanner, with no demonstrated impact # - Missing best-practice headers with no exploit path — still welcome, still triaged, just not treated as a vulnerability # - Third-party services we do not run, which should go to their own program # We do not run a paid bounty. What you get is a reply from somebody # who can fix it, a credit if you want one, and a date for the fix.