Start free trial

Vulnerability Disclosure Policy

Version 1.0 · 1st September 2026 · Last updated: 1st September 2026

VOKT welcomes reports from security researchers who find a genuine vulnerability in our systems, made in good faith and in line with this policy. This policy sets out what is in scope, how to report, and what a researcher can expect from us in return. It follows the approach of ISO/IEC 29147 on vulnerability disclosure.

Scope

In Scope

The public website at vokt.ai

The sign in and account service at vokt.ai

The OCR service at ocr.vokt.ai

VOKT Core on the Shared Cloud and Private Cloud deployment modes, where VOKT operates the infrastructure

Out of Scope

Customer environments running the Own Cloud or Sealed deployment modes, which sit inside the customer's own infrastructure and are not VOKT's to authorise testing on

Infrastructure operated by our hosting and inference providers in their own right, such as Hetzner Online GmbH — report those directly to the relevant provider

Denial of service testing, spam, or any testing that degrades the service for other users

Social engineering of VOKT staff, contractors, or customers

Physical access attempts against VOKT or its hosting providers

How to Report

Send a report to [email protected] The same address should be published in a security.txt file at vokt.ai/.well-known/security.txt, in line with RFC 9116, so researchers can find it without reading this page.

Include enough detail for us to reproduce the issue: the affected URL or system, the steps you took, and what you observed. Where possible, include the minimum proof of concept needed to demonstrate the issue, and avoid accessing more data than necessary to prove it exists.

What We Ask of Researchers

Give us reasonable time to investigate and address an issue before disclosing it publicly

Do not access, modify, or delete data that does not belong to you

Stop testing and report immediately if you encounter personal data, and do not download or retain it

Test only against the in scope systems listed above

Make a good faith effort to avoid privacy violations and service disruption

Our Commitment

We will keep you informed of progress in general terms. We do not commit to sharing internal remediation detail, and we may need more information from you to reproduce or confirm a report.

Safe Harbor

We will not pursue legal action against a researcher who makes a good faith effort to comply with this policy, even if a report turns out to describe a false positive or a duplicate. This does not extend to testing outside the scope described above, or to conduct that breaches the researcher's own local law regardless of this policy.

Coordinated Disclosure

If a confirmed vulnerability involves personal data, we will assess our obligations under Articles 33 and 34 of the General Data Protection Regulation and, where required, notify Datatilsynet and affected individuals in line with the law, independently of anything agreed with the reporting researcher.

Contact

Frostbyte Holding AS,

Årdalsvegen 35, 6884 Øvre Årdal, Norge

Org. nr. 934 881 982

[email protected]

Related documents: our Terms and Conditions set out how the Services may and may not be used; our Privacy Policy explains how we handle personal data submitted with a report.

References

Foudil, E., & Shafranovich, Y. (2022). A file format to aid in security vulnerability disclosure (RFC 9116). Internet Engineering Task Force. https://www.rfc-editor.org/rfc/rfc9116

International Organization for Standardization. (2018). Information technology — Security techniques — Vulnerability disclosure (ISO/IEC 29147:2018). https://www.iso.org/standard/72311.html

Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation), 2016 O.J. (L 119) 1. https://eur-lex.europa.eu/eli/reg/2016/679/oj

Your business, connected.