Dafluma legal
Controlled draft
Security Policy
User security responsibilities and responsible vulnerability reporting.
- Version
- 1.0
- Effective
- 2026-08-06
- Applies to
- Users and security researchers
Controlled draft
This document is versioned but is not a current published policy. Refer to its publication status in the Legal Center.
Protecting your account
- Use a unique password and the strongest available multi-factor authentication.
- Never share OTPs, recovery codes, session cookies, or payment PINs.
- Verify the domain and payment prompt before approving a request.
- Sign out of shared devices and report suspicious activity promptly.
Responsible disclosure
Report a suspected vulnerability privately to security@dafluma.com. Include reproducible detail without accessing more data than necessary. Do not disrupt services, perform social engineering, demand payment, publish secrets, or exploit a vulnerability after confirming it.
What to expect
We aim to acknowledge reports, assess severity, preserve evidence, remediate proportionately, and communicate status where appropriate. This policy is not a bug-bounty promise and does not authorize unlawful testing.