> ## Documentation Index
> Fetch the complete documentation index at: https://docs.doblier.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Vulnerability Disclosure Policy

> How to report security issues in AORBIT or Doblier infrastructure.

## Reporting

Email **[security@doblier.io](mailto:security@doblier.io)** with a description, reproduction steps, and impact assessment. Do not open public issues for security reports.

## Scope

AORBIT software, Doblier-operated infrastructure, and this documentation site. Customer-operated deployments should be reported to the customer's own security team first.

## Response targets

| Stage                         | Target           |
| ----------------------------- | ---------------- |
| Acknowledgement               | 2 business days  |
| Triage & severity             | 5 business days  |
| Remediation plan communicated | per severity SLA |

## Safe harbor

Good-faith research under this policy will not be the subject of legal action. Do not access customer data, degrade availability, or test systems you are not authorized to test.

## Credit

Researchers who report valid issues are credited (with consent) in release notes.
