Skip to content
Security

Vulnerability Disclosure Policy

Updated September 17, 2026

Report a security issue

Email security@versionstory.com with the affected URL or product, a description, reproduction steps, potential impact, and your preferred contact details. Please omit customer data and secrets. If sensitive material is needed, ask us to agree a secure transfer method before sending it.

We aim to acknowledge reports within three business days, provide an initial assessment within ten business days, and update the reporter at least every fourteen days while a confirmed issue remains open. Our current internal remediation targets are thirty days for critical and high findings, sixty for medium, and ninety for low; exceptions are documented and escalated according to company policy.

Research scope and conduct

Research is limited to Version Story-operated application behavior on these exact hosts:

  • Marketing: versionstory.com and www.versionstory.com.
  • Applications: app.versionstory.com and uk.versionstory.com.
  • Public APIs: api.versionstory.com and api.uk.versionstory.com.
  • Application APIs: api-production.versionstory.com and api-production-uk.versionstory.com.
  • Document delivery: documents.versionstory.com and documents-uk.versionstory.com.
  • Comparison connectors: mcp-compare.versionstory.com and mcp-compare-uk.versionstory.com.

This list provides no wildcard authorization. Only Version Story's application and configuration are in scope; customer systems, underlying cloud-provider services, vendor systems and development services are excluded. Testing a customer or vendor integration requires that party's separate authorization.

Use accounts and data you control. Avoid service disruption, denial of service, social engineering, physical attacks and bulk automated traffic. Stop when the issue is demonstrated. If you unexpectedly encounter another party’s information, stop and report the minimum information needed to locate the issue; do not retain, modify or disclose that information. Coordinate public disclosure with us to allow time for investigation and remediation.

We accept reports about our development services as well; active testing there requires prior written scope authorization. Report vendor-hosted service issues directly to the vendor.

Safe-harbor commitment

For good-faith research within the published scope and these conditions, Version Story will treat the activity as authorized and will not initiate legal action against the researcher for that activity. We can speak only for Version Story and cannot authorize activity affecting third parties. If there is doubt about scope, contact us before testing.

Handling reports

The CTO triages reports, records confirmed findings with severity, owner and due date, and escalates suspected compromise under the Incident Response Plan. The CEO coordinates any required external notification. Credit may be provided with the reporter’s permission. No payment or bounty is promised by this policy.