Legal Center
Responsible Disclosure / Security Reporting Policy
How security researchers and customers can report suspected vulnerabilities.
- Effective Date
- August 3, 2026
- Last Revised
- August 3, 2026
- Version
- 1.0
1. Our Commitment
We welcome reports of suspected security vulnerabilities in Diversified Check Studio. This policy explains how to report an issue, what we ask of researchers, and what you can expect from us.
2. Scope
In scope:
- DiversifiedCheckStudio.com and its subdomains operated by us.
- The Diversified Check Studio web application.
- Public endpoints operated by us for webhooks and integrations.
Out of scope:
- Systems operated by our service providers. Report those to the provider directly.
- Findings that require physical access to a user's device, or that depend on a compromised device or browser extension.
- Social engineering of our staff, customers, or vendors.
- Denial of service, volumetric load testing, and automated scanning that degrades service.
- Reports generated solely by automated tools with no demonstrated impact, missing best-practice headers with no exploit path, and version disclosure without a working proof of concept.
3. How to Report
Send your report to the contact address below with the subject line "Security Report". Please include:
- A clear description of the issue and its potential impact.
- Step by step reproduction instructions.
- Affected URLs, endpoints, parameters, or accounts.
- Any proof of concept material, screenshots, or logs.
- How you would like to be credited, if you wish to be credited.
Please encrypt or omit any sensitive customer data from your report, and send only the minimum needed to demonstrate the issue.
4. Rules of Engagement
When testing, you must:
- Use only accounts you own or have explicit permission to test.
- Stop immediately upon encountering another party's personal or financial data, and report it.
- Avoid modifying, deleting, or exfiltrating data belonging to others.
- Avoid degrading service for other users.
- Not use a finding to obtain licenses, entitlements, or premium assets without payment.
- Give us a reasonable opportunity to remediate before any public disclosure.
5. Our Response
We aim to:
- Acknowledge receipt within five business days.
- Provide an initial assessment within ten business days.
- Keep you informed of remediation progress for valid findings.
- Confirm when the issue is resolved.
Remediation timelines depend on severity and complexity. Critical issues are prioritized.
6. Safe Harbor
If you make a good faith effort to comply with this policy, we will not pursue or support legal action against you for your research, and we will treat your activity as authorized under applicable computer access laws. If a third party brings action against you for research conducted in compliance with this policy, we will make that compliance known where we reasonably can.
This safe harbor does not apply to activity that violates the Acceptable Use Policy, harms customers, or continues after we ask you to stop.
7. Rewards
We do not currently operate a paid bug bounty program. We are glad to provide written acknowledgement and, where appropriate and with your consent, public credit.
8. Customer Reports
Customers who suspect their account has been accessed without authorization should contact us immediately using the general support address rather than waiting for a security review, and should change credentials and review account users right away.
9. Changes to This Policy
This policy may be revised. The Last Revised date and version number will be updated when it changes.
10. Contact
Security reports may be sent to:
Diversified Check Studio
A product of Diversified SaaS, Inc.
Diversified SaaS, Inc. is a wholly owned subsidiary of Diversified Universal LLC.
Attention: Security Reports
6212 US Highway 6, Suite 184
Portage, IN 46368-5057
Email: CustomerService@DiversifiedCheckStudio.com
Phone: 1 (833) 990-7297
WhatsApp: 1 (833) 990-7297