Skip to main content
VClick Tools
HomeTrust & LegalSecurity & Disclosure
Trust & Legal

Security & Disclosure

Our security architecture, vulnerability reporting guidelines, and responsible disclosure policy.

Effective Date: August 24, 2026
Last Updated: August 24, 2026
Entity: VClick Digitally

1. Security Architecture & Posture

Security and data privacy are core design principles of VClick Tools, operated by VClick Digitally. Our client-centric architecture minimizes server-side attack surfaces:

  • Browser-Side Data Isolation: Interactive tools process text, JSON payloads, images, and documents locally in browser memory, preventing sensitive draft content from leaking over the network.
  • Transport Security: All HTTP traffic is enforced over TLS/HTTPS with modern cipher suites.
  • Server Security: Backend hosting infrastructure utilizes serverless Edge deployment with automated DDoS mitigation and strict network access rules.

2. Responsible Disclosure Policy

We welcome security researchers and users who inspect our platform to help keep VClick Tools safe. If you believe you have discovered a security vulnerability, we request that you report it to us responsibly following these guidelines:

What to Include in Your Vulnerability Report

  • Detailed description of the suspected vulnerability and affected route or component.
  • Step-by-step proof-of-concept (PoC) steps to reproduce the issue cleanly.
  • Potential security impact assessment.

3. Prohibited Security Testing Activities

While investigating potential security vulnerabilities, you must NOT:

  • Execute Denial-of-Service (DoS / DDoS) attacks or resource flooding against our servers.
  • Access, alter, or destroy data belonging to other users or system infrastructure.
  • Perform social engineering, phishing, or physical attacks against VClick Digitally staff.
  • Publicly disclose a vulnerability before we have been afforded reasonable time to investigate and patch the issue.

4. Our Expected Response Principles

When you report a security vulnerability in adherence to this policy, we commit to:

  • Acknowledging receipt of your security report within 48 hours.
  • Investigating and providing an initial impact assessment within 5 business days.
  • Not taking legal action against researchers who report vulnerabilities in good faith following these guidelines.

5. How to Report a Security Vulnerability

Please submit all security vulnerability reports securely via our Contact Page by selecting the Security Vulnerability Report topic.