← Back to home

Security & Responsible Disclosure

Last updated: 2026-06-29

Reporting a vulnerability

If you believe you have found a security vulnerability in Cloud Doctor, please email support@getclouddoctor.com with details and reproduction steps. Please do not publicly disclose until we have had a reasonable opportunity to respond. We aim to acknowledge reports within 2 business days and to provide a remediation timeline after triage.

Our security posture

Scope

In scope: the Cloud Doctor application, API, and infrastructure we operate. Out of scope: third-party providers (Clerk, Razorpay, AWS) — report those to the respective vendor.