Security
Report a vulnerability
Send vulnerability reports to hello@dossierforge.com.
Version 2026-08-07. It applies from that date.
What this covers
This is the coordinated vulnerability disclosure policy of Skoft Software for DossierForge: the desktop application, this website and the licence check at license.skoft.app. Skoft Software is a sole proprietorship established in the Netherlands and registered with the Kamer van Koophandel under 42097143. The full business identification is on the imprint.
This is not a statement that DossierForge conforms to the Regulation. It is not advice about your product. DossierForge is in private beta and is not on sale, so there is no support period to publish here yet; its end date is stated at the time of purchase, which is when the Regulation asks for it.
Where to report
Write to hello@dossierforge.com.
Include any of these details you have:
- what you found and which version or page you found it on
- how to reproduce it, in whatever detail you have
- what you think it lets an attacker do
- whether you believe it is being exploited already, in the subject line
If the vulnerability is in a third party component we ship rather than in our own code, send it anyway. We report it to whoever maintains that component. Where we write the fix, we share it with them.
When you hear back
You receive an acknowledgement and first assessment within five working days. A fix may take longer.
What happens after you report
We address and remediate without delay. Where it is technically possible, the security update ships separately from feature work, so nobody has to take a release they did not want in order to get a fix. Security updates are free of charge, they are disseminated without delay and each one carries an advisory saying what happened and what a user should do about it.
What we publish and when
Once the update is available we publish what was fixed: a description of the vulnerability, which versions were affected and how to tell, what it allowed, how severe it was and what a user has to do. We name you as the finder unless you would rather we did not.
Timing. We aim to publish within 90 days of your report, or on the day the fix is available, whichever comes first. If a fix genuinely needs longer we say so and agree a date with you instead of letting it drift. Where publishing before users can patch would put them at more risk than it protects them from, we delay the detail until the patch is out. That is the exception Part II, point (4) of Annex I allows. It is the only reason we will use it.
What we ask of you
- Tell us before you tell anyone else and give us the time above.
- Use only your own accounts, your own machine and your own data.
- Do not run denial of service, do not degrade the service for anyone else and do not modify or delete anything that is not yours.
- Go far enough to show the problem is real and no further.
If you keep to that, we will not report you to the police and we will not bring a civil claim against you for the research. We will confirm that in writing if you ask. We can only speak for ourselves: this says nothing about the rights of anyone else whose systems you might touch on the way.
If it is being exploited
When DossierForge is on the market, an actively exploited vulnerability in it, or a severe incident affecting its security, is notified to the CSIRT designated as coordinator and to ENISA at the same time, through the single reporting platform established under Article 16 of the Regulation. An early warning within 24 hours of us becoming aware, a fuller notification within 72 hours and a final report within 14 days of a corrective measure being available, or within one month of the notification where it was an incident. Those reporting obligations start on 11 September 2026.