Security & Vulnerability Disclosure
Reporting a security issue
We take the security of the Velocity factoring-agent portal seriously — it handles non-public financial information. If you believe you’ve found a vulnerability, please report it to us privately so we can address it before it’s disclosed publicly.
How to report
Email athurlow@orangedoorconsulting.net with a description of the issue, the steps to reproduce it, and any relevant logs or screenshots. Encrypt sensitive details if you can.
What to expect
- We acknowledge reports within 24 hours.
- We’ll keep you updated as we investigate and remediate.
- We ask that you give us a reasonable window to fix the issue before any public disclosure, and that you avoid accessing or modifying other users’ data.
Scope
In scope: velocityportal.io and its authenticated application. Please do not run automated scanners that degrade service, attempt denial-of-service, or social-engineer our staff or customers.
Machine-readable contact details are published at /.well-known/security.txt.