Vulnerability disclosure policy

How to report a security problem in Dium safely, and what we promise in return.

Last updated [email protected]
Draft for review. Confirm bracketed items and have counsel review before publishing.

In short

  • Good-faith research under this policy is authorized. We will not pursue legal action.
  • Test only with your own accounts and Flows. Never touch other members' DMs or private Flows.
  • Werify, Werify Paywall, Moat, the database proxy host and Cloudflare are out of scope.
  • We acknowledge reports within 3 business days. No monetary rewards currently.

Introduction

Dium is a community platform built by TAO.ai. We want to hear about security problems in Dium so we can fix them before anyone is harmed. This policy explains what you may test, how to report, and what you can expect from us.

If you follow this policy in good faith, we will treat your research as authorized and will not take legal action against you.

Authorization and safe harbor

If you make a good-faith effort to follow this policy during your research, we will consider it authorized. We will work with you to understand and fix the issue quickly, and Dium will not recommend or pursue legal action related to your research.

For research done under this policy, we consider it to be:

  • Authorized under anti-hacking laws such as the US Computer Fraud and Abuse Act, and we will not bring a claim against you for it.
  • Authorized under anti-circumvention laws, and we will not bring a claim against you for circumventing security controls.
  • Exempt from any restriction in our Terms of Service that would stop you from doing that research. We waive those restrictions for this limited purpose.
  • Lawful and helpful to the security of the internet.

If a third party takes legal action against you for research you did under this policy, we will make it known that your actions were authorized by us. This policy cannot authorize testing of systems we do not own. See scope below.

If you are unsure whether something is allowed, ask us at [email protected] before you go further.

Guidelines

  • Tell us as soon as you find a real or possible issue.
  • Avoid privacy violations, damage to the service, and destroying or changing data.
  • Use an exploit only as far as you need to confirm the issue. Do not use it to go further into our systems, keep access, or move to other systems.
  • Give us a reasonable time to fix the issue before you tell anyone else. We ask for 90 days, and we will agree a date with you.
  • Do not submit a large number of low-quality reports.

Rules specific to a community platform

  • Use only accounts you own. Create your own test Flow and invite your own second account to test anything between members.
  • Do not read, change or delete other members' direct messages, private Flows, invite-only Waves or Page analytics. If you reach any of these by accident, stop, do not keep a copy, and tell us.
  • Do not flag, report or message real members as part of a test. Flags can suspend accounts.
  • Do not post findings inside Dium, for example as a Wave or a reply.

If you find personal data, financial data, credentials or anyone's private messages, stop testing, tell us right away, and do not share the data with anyone.

Test methods

These methods are not allowed:

  • Network denial of service, load testing or anything that degrades Dium for others.
  • Getting around rate limits by spreading traffic over many IPs. Report the rate-limit gap instead.
  • Physical testing of offices or data centers, phishing, social engineering, or any other non-technical attack on staff, members or vendors.
  • Spam, or automated posting into real communities.

Scope

This policy covers the systems below. Anything not listed as in scope is out of scope. Dium relies on other services for sign-in, profiles, payments and delivery. We cannot authorize testing of systems we do not own, so please report their bugs to them.

SystemIn scopeNotes
dium.io and its subdomainsYesThe website, the app under /home/ and /asq/, and the API under /api/
The Dium partner APIYesOnly with a key issued to you for testing. Ask us for one.
Dium code mounted on a partner's siteLimitedReport Dium bugs you see there, but do not test the partner's own servers.
Werify (werify.ai) sign-in and Werify PaywallNoRun by a separate service. We cannot authorize testing it.
Moat (moat.page) profilesNoRun by a separate service. We cannot authorize testing it.
The database proxy hostNoInternal infrastructure. Do not target it directly.
Cloudflare and other vendorsNoReport their bugs to them.

Some reports we usually will not act on, unless you show real impact: missing headers on static pages, clickjacking on pages with no actions, self-XSS, logout CSRF, SPF or DMARC settings, software version banners, and findings from automated scanners without a working example.

Reporting a vulnerability

Email [email protected]. [PGP key: publish a key and fingerprint here and in security.txt, or remove this line]

Please include:

  • Where the issue is (the URL, API action or screen).
  • What someone could do with it.
  • Steps to reproduce it. A short proof of concept helps. Screenshots or a screen recording are welcome.
  • Which of your test accounts and Flows you used.

You can report without giving your name. If you do, we cannot send you updates. Please write in English.

What you can expect from us

When you give us a way to contact you, we will:

  • Acknowledge your report within 3 business days.
  • Confirm whether the issue is real and tell you what we plan to do, within [triage target, e.g. 10 business days].
  • Keep you updated as we work on the fix, and tell you when it ships.
  • Credit you in the hall of fame below if you want, once the issue is fixed.

We want to be open about fixes, and we may publish a short write-up once an issue is resolved. We will check the wording with you first.

Rewards

Dium does not currently pay monetary rewards for reports. This is a disclosure policy, not a paid bug bounty. We offer public credit instead. If that changes, we will say so on this page first.

Hall of fame

Researchers who reported a valid issue under this policy, with their permission.

No reports have been credited yet.

Credit is added after the fix ships.

Questions

Questions about this policy, or ideas to improve it, go to [email protected]. You can also read our security overview.

Document history: first published September 28, 2026.