Tue. Sep 1st, 2026

Security and Vulnerability Disclosure

Our Commitment

The Data Verdict values responsible security research that helps protect our readers, contributors, sources, editorial systems, and digital infrastructure.

This policy explains how to report suspected security vulnerabilities affecting technology controlled by The Data Verdict and establishes the conditions under which good-faith security research may be conducted.

This policy does not authorize access to third-party systems, disruption of services, collection of unrelated information, or activity that violates applicable law. If you are uncertain whether a particular test is permitted, stop testing and contact us before continuing.

Scope

The scope of this policy includes thedataverdict.com, its subdomains, applications, APIs, and other digital services that The Data Verdict expressly identifies as under its control.

Third-party services—including hosting providers, analytics platforms, payment processors, advertising networks, content-delivery networks, social platforms, email providers, and embedded services—are outside the scope of this policy unless The Data Verdict explicitly confirms otherwise.

If a suspected vulnerability exists in a third-party service but may materially affect The Data Verdict users, you may provide a limited description of the issue. We may coordinate with the relevant provider, but this policy does not grant permission to test or access systems operated by that provider.

Good-Faith Security Research

Security researchers are expected to make reasonable efforts to minimize harm while validating a suspected vulnerability.

Researchers should:

  • Use the smallest practical proof of concept.
  • Avoid accessing information that is not necessary to demonstrate the vulnerability.
  • Stop testing if sensitive personal, financial, editorial, source, or authentication data is encountered.
  • Avoid modifying, deleting, or corrupting data.
  • Avoid degrading or interrupting website availability.
  • Delete or securely dispose of information obtained accidentally during testing when it is no longer required for the report.
  • Report the vulnerability promptly after sufficient evidence has been collected.

Researchers must not:

  • Establish persistence or maintain unauthorized access.
  • Pivot from one system to another.
  • Access confidential editorial material or source communications.
  • Download databases or bulk personal information.
  • Alter published content or website configuration.
  • Conduct denial-of-service or resource-exhaustion testing.
  • Send spam or mass automated requests.
  • Conduct phishing, social engineering, or impersonation attacks.
  • Test physical security controls.
  • Upload malware or deploy malicious code.
  • Attempt to access systems outside the stated scope.
  • Use a vulnerability to obtain a financial benefit.
  • Demand payment or other consideration in exchange for withholding vulnerability information.

Safe-Harbor Statement

When security research is conducted in good faith, remains within the scope of this policy, avoids unnecessary harm, and is reported through the designated disclosure process, The Data Verdict will not initiate legal action solely because the researcher performed authorized security testing under these conditions.

Where appropriate and lawful, we may explain to a third party that the activity was conducted as part of our vulnerability disclosure process.

This safe-harbor provision does not bind third parties, law-enforcement authorities, courts, regulators, or other organizations. It also does not protect malicious, deceptive, extortionate, reckless, unauthorized, or otherwise unlawful conduct.

How to Report a Vulnerability

Security vulnerabilities should be reported to:

security@thedataverdict.com

Please use a subject such as “Security Vulnerability Report” and provide enough information for our team to understand and safely reproduce the issue.

A useful report should include:

  • The affected URL, application, API, or asset.
  • A description of the vulnerability.
  • The vulnerability category or suspected cause, if known.
  • Clear steps to reproduce the issue.
  • The observed and potential security impact.
  • The date and approximate time of testing.
  • Relevant browser, operating-system, or testing-tool information.
  • A minimal proof of concept demonstrating the issue.
  • Suggested remediation, where available.

Please do not send unnecessary databases, credentials, private communications, identity documents, or other sensitive personal information.

If sensitive evidence is necessary to demonstrate the vulnerability, contact us first so that an appropriate secure or encrypted communication channel can be arranged.

Where supported, The Data Verdict may publish a valid /.well-known/security.txt file identifying the current security contact, policy location, preferred communication language, and policy review or expiry information.

Response Targets

We aim to acknowledge credible vulnerability reports within three business days and provide an initial assessment within ten business days.

Where remediation is required, we aim to communicate material status changes while the issue is being addressed.

These are operational targets rather than guarantees. Complex vulnerabilities, third-party dependencies, holidays, active security incidents, or other exceptional circumstances may require additional time.

Vulnerabilities are prioritized according to factors including:

  • Exploitability
  • Severity and affected systems
  • Type and sensitivity of exposed data
  • Number and type of potentially affected users
  • Required privileges or authentication
  • Potential persistence
  • Availability or integrity impact
  • Availability of mitigations or workarounds

Coordinated Disclosure

Researchers are encouraged to allow reasonable time for investigation and remediation before publicly disclosing a vulnerability.

The Data Verdict will seek to discuss an appropriate disclosure timeline in good faith, particularly where remediation involves third-party providers or significant changes to production systems.

Immediate public disclosure may be appropriate in exceptional circumstances where users face active harm and the publisher is not responding. However, researchers should avoid publishing exploit details, credentials, personal information, or other material that could unnecessarily increase risk.

Where appropriate, The Data Verdict may publicly credit researchers who responsibly disclose vulnerabilities, subject to the researcher’s consent.

The Data Verdict does not promise a monetary bounty, employment, compensation, or public recognition unless such an arrangement has been expressly agreed in writing beforehand.

Out-of-Scope Findings

The following findings are generally outside the primary scope of this disclosure process when they do not demonstrate a meaningful security impact:

  • Missing security headers without an exploitable consequence.
  • Clickjacking on pages where no sensitive action can be performed.
  • Self-XSS.
  • Rate-limit observations without demonstrated security impact.
  • Automated scanner findings that have not been manually validated.
  • Username or account enumeration without additional material impact.
  • Email-authentication configuration observations without demonstrated exploitability.
  • Vulnerabilities existing solely in unsupported third-party components that The Data Verdict does not control.

An issue may still be reviewed when additional evidence demonstrates a credible risk to users, data, systems, or publication operations.

Incident and Privacy Handling

Security reports are handled on a need-to-know basis. Information may be shared with authorized personnel, technical providers, legal advisers, insurers, incident-response specialists, or other parties where reasonably necessary for investigation, remediation, security, or legal compliance.

Security records may be retained for an appropriate period for verification, remediation, accountability, audit, legal requirements, and future security improvements.

Personal information contained in a security report will be minimized where practical and handled in accordance with The Data Verdict’s Privacy Policy.

Contact

Security & Vulnerability Reports
security@thedataverdict.com

Privacy & Data Protection
privacy@thedataverdict.com

Editorial & Source Security
editorial@thedataverdict.com

Security vulnerabilities should be reported to security@thedataverdict.com. Privacy concerns unrelated to a security vulnerability should be sent to privacy@thedataverdict.com. Concerns involving editorial systems, confidential sources, newsroom security, or sensitive reporting should be directed to editorial@thedataverdict.com.

Please do not send passwords, unnecessary personal information, complete databases, or other sensitive material unless specifically requested through an approved secure channel.

This policy is reviewed periodically and may be updated as The Data Verdict’s technology, security practices, and vulnerability-disclosure procedures evolve.