Flireo B.V. (VoiceDock) welcomes reports from security researchers. This policy explains how to report a vulnerability and what you can expect from us.
How to report
Email security@flireo.com. Please include:
- a description of the vulnerability and where you found it;
- steps to reproduce, or a proof of concept;
- the potential impact as you see it;
- any suggested remediation.
Our machine-readable contact is published at
/.well-known/security.txt.
Our commitment
- We will acknowledge your report within 3 business days.
- We will give you an initial assessment — whether we can reproduce it and how we rate the severity — within 10 business days.
- We will keep you informed of progress at reasonable intervals until it is closed.
- We will remediate confirmed issues as quickly as is practical, prioritised by severity, and tell you when the fix is live.
- We will credit you if you wish, once the issue is resolved.
We are a small team, so these are commitments we can actually keep rather than aspirational targets.
Safe harbour
If you make a good-faith effort to comply with this policy, we will not pursue or support legal action against you for your research. Good faith means: you avoid privacy violations, data destruction, and service disruption; you only interact with accounts you own or have explicit permission to test; and you give us a reasonable opportunity to fix the issue before disclosing it publicly.
Please do not
- Access, modify, or delete data that is not yours.
- Run denial-of-service tests, spam, or high-volume automated scans against the live platform or the telephone network.
- Use social engineering, phishing, or physical attacks against our staff or offices.
- Publicly disclose the issue before we have had a reasonable chance to fix it.
Scope
In scope: the VoiceDock platform, dashboard, API, and this trust center.
Out of scope:
- Third-party services and sub-processors (report those to the provider).
- Findings that require an already-compromised device, mailbox, or account.
- Issues in integrations a Customer configured themselves.
- Raw scanner output without a demonstrated, exploitable impact, and reports that amount to a list of missing best-practice headers with no attack path.
- Missing rate limiting or brute-force protection reported without a working demonstration of impact.
- Social engineering, spam, and reports about email deliverability configuration on domains we do not control.
Reward
We do not currently operate a paid bug-bounty programme, but we genuinely value coordinated disclosure and will credit researchers who help us keep VoiceDock secure.