Vulnerability Disclosure Policy
Version 1.0 · 1st September 2026 · Last updated: 1st September 2026
VOKT welcomes reports from security researchers who find a genuine vulnerability in our systems, made in good faith and in line with this policy. This policy sets out what is in scope, how to report, and what a researcher can expect from us in return. It follows the approach of ISO/IEC 29147 on vulnerability disclosure.
Scope
In Scope
The public website at vokt.ai
The sign in and account service at vokt.ai
The OCR service at ocr.vokt.ai
VOKT Core on the Shared Cloud and Private Cloud deployment modes, where VOKT operates the infrastructure
Out of Scope
Customer environments running the Own Cloud or Sealed deployment modes, which sit inside the customer's own infrastructure and are not VOKT's to authorise testing on
Infrastructure operated by our hosting and inference providers in their own right, such as Hetzner Online GmbH — report those directly to the relevant provider
Denial of service testing, spam, or any testing that degrades the service for other users
Social engineering of VOKT staff, contractors, or customers
Physical access attempts against VOKT or its hosting providers
How to Report
Send a report to [email protected] The same address should be published in a security.txt file at vokt.ai/.well-known/security.txt, in line with RFC 9116, so researchers can find it without reading this page.
Include enough detail for us to reproduce the issue: the affected URL or system, the steps you took, and what you observed. Where possible, include the minimum proof of concept needed to demonstrate the issue, and avoid accessing more data than necessary to prove it exists.
What We Ask of Researchers
Give us reasonable time to investigate and address an issue before disclosing it publicly
Do not access, modify, or delete data that does not belong to you
Stop testing and report immediately if you encounter personal data, and do not download or retain it
Test only against the in scope systems listed above
Make a good faith effort to avoid privacy violations and service disruption
Our Commitment
We will keep you informed of progress in general terms. We do not commit to sharing internal remediation detail, and we may need more information from you to reproduce or confirm a report.
Safe Harbor
We will not pursue legal action against a researcher who makes a good faith effort to comply with this policy, even if a report turns out to describe a false positive or a duplicate. This does not extend to testing outside the scope described above, or to conduct that breaches the researcher's own local law regardless of this policy.
Coordinated Disclosure
If a confirmed vulnerability involves personal data, we will assess our obligations under Articles 33 and 34 of the General Data Protection Regulation and, where required, notify Datatilsynet and affected individuals in line with the law, independently of anything agreed with the reporting researcher.
Contact
Frostbyte Holding AS,
Årdalsvegen 35, 6884 Øvre Årdal, Norge
Org. nr. 934 881 982
Related documents: our Terms and Conditions set out how the Services may and may not be used; our Privacy Policy explains how we handle personal data submitted with a report.
References
Foudil, E., & Shafranovich, Y. (2022). A file format to aid in security vulnerability disclosure (RFC 9116). Internet Engineering Task Force. https://www.rfc-editor.org/rfc/rfc9116
International Organization for Standardization. (2018). Information technology — Security techniques — Vulnerability disclosure (ISO/IEC 29147:2018). https://www.iso.org/standard/72311.html
Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation), 2016 O.J. (L 119) 1. https://eur-lex.europa.eu/eli/reg/2016/679/oj