Vulnerability Disclosure Policy
At Phone Verif, security is a fundamental part of our product.
We appreciate the work of security researchers and the wider security community in helping us identify and resolve potential vulnerabilities. We encourage responsible disclosure of security issues and are committed to working with researchers to investigate and address reported vulnerabilities.
For a deeper look at how we secure the platform, read How Phone Verif secures WhatsApp phone verification.
Reporting a vulnerability
If you believe you have discovered a security vulnerability affecting Phone Verif, please email security@phone-verif.com.
Please include:
- A description of the vulnerability.
- The affected component or endpoint.
- Steps required to reproduce the issue.
- The potential impact.
- Any relevant logs, screenshots, or proof-of-concept examples.
- Your contact information for follow-up.
Providing detailed reproduction steps helps us investigate and resolve issues faster.
Our commitment
When you report a security issue, we commit to:
- Acknowledge receipt of your report within 3 business days.
- Investigate the issue in good faith.
- Provide updates as our investigation progresses.
- Work toward remediation as quickly as possible.
- Credit researchers who responsibly disclose vulnerabilities, unless they prefer to remain anonymous.
Responsible testing guidelines
When researching potential vulnerabilities, we ask that you:
- Avoid accessing, modifying, or deleting data belonging to other users.
- Avoid disrupting service availability.
- Avoid automated testing that generates excessive traffic.
- Avoid social engineering attacks against Phone Verif employees, customers, or users.
- Stop testing and report the issue once you have sufficient information to demonstrate the vulnerability.
Safe harbor
We will not take legal action against researchers who:
- Act in good faith.
- Follow this policy.
- Avoid privacy violations and service disruption.
- Give us reasonable time to investigate and resolve reported issues before public disclosure.
Testing performed outside these guidelines may not qualify for safe harbor.
Scope
This policy applies to vulnerabilities affecting:
- Phone Verif APIs.
- Phone verification flows.
- Customer dashboards.
- Authentication mechanisms.
- Publicly accessible Phone Verif infrastructure.
Third-party services used by Phone Verif may have their own vulnerability reporting procedures.
Disclosure timeline
We prefer coordinated disclosure. After receiving a valid report:
- We confirm receipt.
- We validate and assess the impact.
- We develop and deploy a fix.
- We coordinate public disclosure when appropriate.
We ask researchers to allow reasonable time for remediation before publishing vulnerability details.
Recognition
We appreciate researchers who help improve Phone Verif security.
With permission, we may publicly recognize contributors who responsibly disclose vulnerabilities.