Skip to content
QA environmentSynthetic test data. Sandboxed email / SMS / fax / Stripe. Safe to break.

Security

Protecting the documents and data our customers entrust to us is the core of what SLDocs does.

How your data is protected

Reporting a vulnerability

If you believe you have found a security vulnerability in SLDocs, we want to hear from you. Please email security@sldocs.com with enough detail to reproduce the issue — affected URL or endpoint, steps, and impact. We aim to acknowledge reports within 3 business days.

Please don't email sensitive personal or health information or documents — email isn't encrypted and may be stored outside the U.S. Use your in-product vault instead.

Please give us a reasonable opportunity to investigate and remediate before disclosing publicly. We practice coordinated disclosure and will keep you updated on our progress.

Good-faith safe harbor

We will not pursue or support legal action against researchers who, in good faith, follow this policy: access only their own test data, avoid privacy violations and service degradation, and do not exfiltrate or destroy data. If in doubt, ask us first at the address above.

Please do not

Out of scope

Machine-readable contact details are published at /.well-known/security.txt (RFC 9116).