Vulnerability Disclosure Policy

Introduction

Docly Serviços de Informática Ltda., registered under CNPJ No. 30.021.390/0001-47, takes the security of its systems and of the data under its responsibility seriously. This policy describes how to report a security vulnerability in our systems, and the limits and conditions that apply.

Scope

This policy applies to the following domains and to the services hosted on them:

  • docly.com.br
  • doclyassist.com.br
  • doclysign.com.br

Third-party systems, contracted services and external provider infrastructure fall outside the scope of this policy, even where reachable from the domains above. Domains operated by other legal entities, including related ones, have their own policy and are not covered by this document.

No financial reward

Docly does not operate a bug bounty program and does not offer any reward, payment, prize or financial compensation of any kind for vulnerability reports.

Submitting a report, whether solicited or not, creates no payment obligation for Docly and no legitimate expectation of remuneration. Reports are received and assessed solely on their technical merit.

How to report

Send your report to [email protected], in Portuguese, Spanish or English, including:

  • Technical description of the vulnerability
  • Affected domain, URL or component
  • Steps to reproduce
  • Objective evidence (request and response, log, screenshot)
  • Estimated potential impact

Reports consisting solely of raw automated-tool output, without analysis or validation of exploitability, will not be processed.

Unauthorized conduct

The following acts are not authorized and may constitute unauthorized access to a computer system under applicable Brazilian law:

  • Performing active testing, scanning, fuzzing or exploitation attempts against our systems without prior written authorization from Docly
  • Accessing, copying, modifying, exfiltrating or retaining third-party data
  • Degrading, disrupting or attempting to deny the availability of any service
  • Using social engineering against employees, customers or suppliers
  • Physically accessing facilities of Docly or its customers
  • Publicly disclosing a vulnerability before it is remediated, without prior agreement with Docly

Submitting a report does not constitute retroactive authorization for the acts above.

Conditioning a report on payment

Docly does not negotiate the receipt of security reports. Communications that condition the delivery of vulnerability information on payment, or that suggest public disclosure or contact with customers or regulators as a form of pressure, will be treated as attempted coercion, preserved as evidence, and referred to our legal department and to the competent authorities.

Our response

Upon receiving a report within the terms of this policy, Docly will:

  • Acknowledge receipt within 10 (ten) business days
  • Technically assess the report and state whether it was considered valid
  • Remediate confirmed issues within a timeframe consistent with their severity
  • Take no legal action against anyone who acted in good faith and in full compliance with this policy

The last item does not apply to anyone who performed active testing without prior written authorization, accessed third-party data, or conditioned the report on payment.

Acknowledgement

Upon request, Docly may publicly acknowledge the contribution of anyone reporting a valid vulnerability. Acknowledgement is discretionary, unpaid, and creates no relationship of any kind.

Effective version

This policy may be amended at any time. The version in force is the one published on this page.

Docly Serviços de Informática Ltda. — CNPJ 30.021.390/0001-47 — Version 1.0 — 28 August 2026