LedgerDo LedgerDo
Sign in Create account

Security Policy

LedgerDo supports responsible disclosure and welcomes reports of security vulnerabilities affecting our platform, website, or supporting services.

How to Report a Vulnerability

Email [email protected] with a clear description of the issue. Use the subject line "Security Report" if possible so we can triage it quickly.

What to Include

  • A summary of the vulnerability and the affected URL, feature, endpoint, or component.
  • Steps to reproduce the issue, including any prerequisites or account state required.
  • The potential impact you observed or reasonably believe is possible.
  • Proof-of-concept details, screenshots, logs, or request and response samples where helpful.
  • Your name or handle and how you would like us to follow up.

Responsible Disclosure Expectations

LedgerDo supports responsible disclosure. We ask researchers to act in good faith, avoid privacy violations and service disruption, and give us a reasonable opportunity to investigate and remediate reported issues.

No bug bounty or compensation is currently offered unless LedgerDo explicitly states otherwise in writing.

Testing Boundaries

Researchers must not access, modify, delete, or exfiltrate customer data.

The following activities are not permitted:

  • Denial-of-service or resource exhaustion testing.
  • Spam, phishing, or social engineering against LedgerDo staff, users, or customers.
  • Physical attacks against offices, employees, contractors, or infrastructure.
  • Any attempt to persist, broaden, or weaponize access beyond what is necessary to demonstrate a finding.
© 2026 LedgerDo — All rights reserved Terms Privacy Security SMS Consent Data Deletion Contact