DOKU · Vulnerability Disclosure

Doku Vulnerability Disclosure

Vulnerability disclosure

DOKU publishes a vulnerability disclosure policy for reporting security issues. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.

PaymentsPayment GatewayFintechIndonesiaSEASNAPVirtual AccountE-WalletQRISDirect DebitPayouts
Program: security.txt present

Disclosure Policy

Security Contact

Contact
{"note" => "General/merchant support contact; no dedicated security reporting address is published.", "type" => "general-support", "url" => "https://www.doku.com/en-us/contact-us"}

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-07-17'
method: searched
probe: true
source: https://doku.com/.well-known/security.txt (probe) + developer/security docs
securityTxt:
  present: false
  probedUrl: https://doku.com/.well-known/security.txt
  httpStatus: 301
  note: No security.txt is served; the well-known path redirects and does not return a policy.
disclosureProgram:
  found: false
  note: >-
    No public vulnerability disclosure program, bug-bounty, or responsible-
    disclosure policy was found on doku.com, developers.doku.com, or
    docs.doku.com as of the review date. DOKU maintains PCI DSS Level 1 and
    ISO/IEC 27001 controls but does not publish a coordinated-disclosure
    channel or a security.txt contact.
contact:
- type: general-support
  url: https://www.doku.com/en-us/contact-us
  note: General/merchant support contact; no dedicated security reporting address is published.
evidence:
- source: https://doku.com/.well-known/security.txt
  kind: security.txt (live probe, HTTP 301, no policy returned)
- source: https://docs.doku.com/security/licenses
  kind: security/licenses page (certifications only, no VDP)